Skip to content

Update module golang.org/x/oauth2 to v0.27.0 [SECURITY]#108

Open
renovate[bot] wants to merge 1 commit intomainfrom
renovate/go-golang.org-x-oauth2-vulnerability
Open

Update module golang.org/x/oauth2 to v0.27.0 [SECURITY]#108
renovate[bot] wants to merge 1 commit intomainfrom
renovate/go-golang.org-x-oauth2-vulnerability

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Jul 18, 2025

This PR contains the following updates:

Package Change Age Confidence
golang.org/x/oauth2 v0.26.0v0.27.0 age confidence

GitHub Vulnerability Alerts

CVE-2025-22868

An attacker can pass a malicious malformed token which causes unexpected memory to be consumed during parsing.


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot enabled auto-merge (squash) July 18, 2025 18:32
@renovate
Copy link
Contributor Author

renovate bot commented Jul 18, 2025

ℹ Artifact update notice

File name: go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • The go directive was updated for compatibility reasons

Details:

Package Change
go 1.13 -> 1.23.0

@renovate renovate bot force-pushed the renovate/go-golang.org-x-oauth2-vulnerability branch 4 times, most recently from be7c2a9 to 18982ad Compare August 13, 2025 08:37
@renovate renovate bot force-pushed the renovate/go-golang.org-x-oauth2-vulnerability branch 2 times, most recently from 9646fd7 to 7e862c0 Compare September 7, 2025 01:31
@renovate renovate bot force-pushed the renovate/go-golang.org-x-oauth2-vulnerability branch from 7e862c0 to 52fccb2 Compare November 20, 2025 21:09
@renovate renovate bot force-pushed the renovate/go-golang.org-x-oauth2-vulnerability branch from 52fccb2 to e79f390 Compare December 4, 2025 07:08
@renovate
Copy link
Contributor Author

renovate bot commented Dec 15, 2025

ℹ️ Artifact update notice

File name: go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • The go directive was updated for compatibility reasons

Details:

Package Change
go 1.13 -> 1.23.0

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants