Skip to content

chore: update quic-go import#12734

Closed
rsmitty wants to merge 1 commit into
siderolabs:mainfrom
rsmitty:quic-go
Closed

chore: update quic-go import#12734
rsmitty wants to merge 1 commit into
siderolabs:mainfrom
rsmitty:quic-go

Conversation

@rsmitty

@rsmitty rsmitty commented Feb 6, 2026

Copy link
Copy Markdown
Member

This PR bumps the quick-go import to protect from CVE-2025-64702 (found via dependabot alerts).

@github-project-automation github-project-automation Bot moved this to To Do in Planning Feb 6, 2026
@talos-bot talos-bot moved this from To Do to In Review in Planning Feb 6, 2026

@frezbo frezbo left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I wonder if we should do go-vulncheck for all go.mod, cc @smira

@github-project-automation github-project-automation Bot moved this from In Review to Approved in Planning Feb 6, 2026
@smira

smira commented Feb 6, 2026

Copy link
Copy Markdown
Member

I think this is all false positives

This PR bumps the quick-go import to protect from CVE-2025-64702 (found via dependabot alerts).

Signed-off-by: Spencer Smith <spencer.smith@talos-systems.com>
@smira

smira commented Feb 6, 2026

Copy link
Copy Markdown
Member

I'll add a bigger bump of tools which will resolve this, I just need to handle one edge case issue.

@smira smira closed this Feb 6, 2026
@github-project-automation github-project-automation Bot moved this from Approved to Done in Planning Feb 6, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Archived in project

Development

Successfully merging this pull request may close these issues.

4 participants