Skip to content

[release-3.19] chore(deps): bump golang.org/x/crypto from 0.41.0 to 0.43.0#31407

Merged
gjenkins8 merged 1 commit into
helm:release-3.19from
dirkmueller:release-3.19
Oct 28, 2025
Merged

[release-3.19] chore(deps): bump golang.org/x/crypto from 0.41.0 to 0.43.0#31407
gjenkins8 merged 1 commit into
helm:release-3.19from
dirkmueller:release-3.19

Conversation

@dirkmueller

@dirkmueller dirkmueller commented Oct 20, 2025

Copy link
Copy Markdown
Contributor

This is needed to update x/net which is subject to CVE-2025-47911

What this PR does / why we need it:

Resolves a CVE report in a dependency.

Special notes for your reviewer:

If applicable:

  • this PR contains user facing changes (the docs needed label should be applied if so)
  • this PR contains unit tests
  • this PR has been tested for backwards compatibility

This is needed to update x/net which is subject to CVE-2025-47911

Signed-off-by: Dirk Müller <dirk@dmllr.de>

@robertsirc robertsirc left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@robertsirc robertsirc added the Has One Approval This PR has one approval. It still needs a second approval to be merged. label Oct 21, 2025
@gjenkins8

Copy link
Copy Markdown
Member

Can you link the CVE for posterity please

@pull-request-size pull-request-size Bot added the size/S Denotes a PR that changes 10-29 lines, ignoring generated files. label Oct 27, 2025
@dirkmueller

Copy link
Copy Markdown
Contributor Author

Can you link the CVE for posterity please

in the PR or in the commit message? I've linked it in the PR above.

@gjenkins8

Copy link
Copy Markdown
Member

Can you link the CVE for posterity please

in the PR or in the commit message? I've linked it in the PR above.

sorry, too much multi-tasking. missed that.

@gjenkins8 gjenkins8 merged commit 3f5d2e2 into helm:release-3.19 Oct 28, 2025
2 checks passed
@gjenkins8 gjenkins8 removed the Has One Approval This PR has one approval. It still needs a second approval to be merged. label Oct 28, 2025
@scottrigby scottrigby added the dependencies Pull requests that update a dependency file label Nov 4, 2025
@scottrigby scottrigby added this to the 4.0.0 milestone Nov 4, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file size/S Denotes a PR that changes 10-29 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants