Skip to content

Bump golang.org/x/net to v0.47.0 to fix CVE-2025-47911#284

Open
drizzd wants to merge 1 commit intovmware-tanzu:mainfrom
drizzd:CVE-2025-47911
Open

Bump golang.org/x/net to v0.47.0 to fix CVE-2025-47911#284
drizzd wants to merge 1 commit intovmware-tanzu:mainfrom
drizzd:CVE-2025-47911

Conversation

@drizzd
Copy link
Copy Markdown

@drizzd drizzd commented Feb 24, 2026

No description provided.

Signed-off-by: Clemens Buchacher <drizzd@gmx.net>
@drizzd
Copy link
Copy Markdown
Author

drizzd commented Mar 8, 2026

@shubham-pampattiwar velero-plugin-for-aws is the last dependency which has not patched this CVE yet. What is the project policy for security updates? We will use this information to evaluate our dependencies. Thanks.

@kaovilai
Copy link
Copy Markdown
Collaborator

base branch updated.. check if this is still needed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants