Repository navigation
fix(deps): bump golang.org/x/text to v0.39.0 (GO-2026-5970) - #1484
Conversation
golang.org/x/text v0.38.0 is affected by GO-2026-5970, an infinite loop
on invalid input in the norm package. govulncheck flags it as reachable
via:
- internal/server/scheduledauth/validator.go:269
(Validator.Warmup -> http.Client.Do -> norm.Form.*)
- internal/database/connection.go:319
(Connection.TryAdvisoryLock -> pgxpool.Acquire -> norm.Form.*)
This reddens the Security Scanning job on main and every PR.
Bump the indirect x/text dependency to v0.39.0 (fixed version) in the
three modules that pin it: root, providers/azure, providers/gcp. The
go directive is left untouched in all three, per repo policy (bumping
it breaks the gosec Docker action's bundled Go toolchain).
Clears GO-2026-5970 from govulncheck across all 6 CI-scanned modules
(root, pkg, providers/aws, providers/azure, providers/gcp, tests/e2e).
|
@coderabbitai review |
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Run ID: ⛔ Files ignored due to path filters (3)
📒 Files selected for processing (3)
📝 WalkthroughWalkthroughThe pull request updates the indirect ChangesGo module dependency alignment
Estimated code review effort: 1 (Trivial) | ~2 minutes 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
✅ Action performedReview finished.
|
|
@coderabbitai full review |
✅ Action performedFull review finished. |
|
Ready for human merge.
Recommend a human merge. Merging this first also clears the same pre-existing Security Scanning red on PR #394 once that branch rebases onto main. Note: a separate non-reachable advisory GO-2026-5932 (x/crypto/openpgp unmaintained-package warning) remains on main and is out of scope here; worth a follow-up but does not fail the gate. |
golang.org/x/text v0.38.0 is affected by GO-2026-5970, an infinite loop
on invalid input in the norm package. govulncheck flags it as reachable
via:
- internal/server/scheduledauth/validator.go:269
(Validator.Warmup -> http.Client.Do -> norm.Form.*)
- internal/database/connection.go:319
(Connection.TryAdvisoryLock -> pgxpool.Acquire -> norm.Form.*)
This reddens the Security Scanning job on main and every PR.
Bump the indirect x/text dependency to v0.39.0 (fixed version) in the
three modules that pin it: root, providers/azure, providers/gcp. The
go directive is left untouched in all three, per repo policy (bumping
it breaks the gosec Docker action's bundled Go toolchain).
Clears GO-2026-5970 from govulncheck across all 6 CI-scanned modules
(root, pkg, providers/aws, providers/azure, providers/gcp, tests/e2e).
Summary
golang.org/x/text@v0.38.0is affected by GO-2026-5970 (infinite loop on invalid input in thenormpackage), fixed in v0.39.0.internal/server/scheduledauth/validator.go:269(Validator.Warmup->http.Client.Do->norm.Form.*)internal/database/connection.go:319(Connection.TryAdvisoryLock->pgxpool.Acquire->norm.Form.*)Security Scanningjob (CI - Build & Test) onmainand every PR.x/textdependency tov0.39.0in the three modules that pin it: rootgo.mod,providers/azure/go.mod,providers/gcp/go.mod.pkg,providers/aws, andtests/e2edo not depend onx/textand needed no change.godirective is left untouched in all three modules (bumping it breaks the gosec Docker action's bundled Go toolchain per prior repo incident).No existing tracking issue found for this specific CVE (searched
x/text,GO-2026-5970,govulncheck); closest related issues are #1285 (pgx CVE, different advisory, closed via prior fix) and LeanerCloud/cloud-commitments-platform#74 (govulncheck retry hardening, unrelated). Not closing either.Test plan
go get golang.org/x/text@v0.39.0 && go mod tidyin root,providers/azure,providers/gcp— clean diffs, single-linex/textbump each, no unexpected transitive changesgovulncheck@v1.1.4 ./...(pinned to match CI) run in all 6 CI-scanned modules (root,pkg,providers/aws,providers/azure,providers/gcp,tests/e2e) — exit 0 in all, GO-2026-5970 no longer reported anywherego build ./...— exit 0 in root,providers/azure,providers/gcpgo vet ./...— exit 0 in root--no-verify)Summary by CodeRabbit