From 02bb1602a737324e5d5d7bf7097fa1a835ce563a Mon Sep 17 00:00:00 2001 From: Sukhbir Singh Date: Mon, 18 May 2026 13:09:13 +0530 Subject: [PATCH] deps: bump golang.org/x/net to v0.53.0 [release-4.2] Backports the golang.org/x/net upgrade already present on main (commit on main bumped to v0.53.0). The v0.52.0 currently pinned in release-4.2 is affected by GO-2026-4918, a HTTP/2 vulnerability in golang.org/x/net/http2 fixed in v0.53.0. This affects any downstream image that ships the helm v4.2.x binary: vulnerability scanners (Trivy, MS S360, etc.) flag the embedded golang.org/x/net version even though helm's own code paths may not be exploitable. A patch release on release-4.2 that includes this bump lets downstream consumers clear the finding without waiting for v4.3.0. Verified locally with go 1.26.3 on windows/amd64: go get golang.org/x/net@v0.53.0 go mod tidy go build ./... # passes Refs: https://pkg.go.dev/vuln/GO-2026-4918 Signed-off-by: Sukhbir Singh --- go.mod | 2 +- go.sum | 4 ++-- 2 files changed, 3 insertions(+), 3 deletions(-) diff --git a/go.mod b/go.mod index 40c02c7e1..3fc1c1536 100644 --- a/go.mod +++ b/go.mod @@ -158,7 +158,7 @@ require ( go.opentelemetry.io/proto/otlp v1.10.0 // indirect go.yaml.in/yaml/v2 v2.4.3 // indirect golang.org/x/mod v0.34.0 // indirect - golang.org/x/net v0.52.0 // indirect + golang.org/x/net v0.53.0 // indirect golang.org/x/oauth2 v0.36.0 // indirect golang.org/x/sync v0.20.0 // indirect golang.org/x/sys v0.43.0 // indirect diff --git a/go.sum b/go.sum index f1a2ca9f8..cc272f4b6 100644 --- a/go.sum +++ b/go.sum @@ -400,8 +400,8 @@ golang.org/x/net v0.10.0/go.mod h1:0qNGK6F8kojg2nk9dLZ2mShWaEBan6FAoqfSigmmuDg= golang.org/x/net v0.15.0/go.mod h1:idbUs1IY1+zTqbi8yxTbhexhEEk5ur9LInksu6HrEpk= golang.org/x/net v0.17.0/go.mod h1:NxSsAGuq816PNPmqtQdLE42eU2Fs7NoRIZrHJAlaCOE= golang.org/x/net v0.18.0/go.mod h1:/czyP5RqHAH4odGYxBJ1qz0+CE5WZ+2j1YgoEo8F2jQ= -golang.org/x/net v0.52.0 h1:He/TN1l0e4mmR3QqHMT2Xab3Aj3L9qjbhRm78/6jrW0= -golang.org/x/net v0.52.0/go.mod h1:R1MAz7uMZxVMualyPXb+VaqGSa3LIaUqk0eEt3w36Sw= +golang.org/x/net v0.53.0 h1:d+qAbo5L0orcWAr0a9JweQpjXF19LMXJE8Ey7hwOdUA= +golang.org/x/net v0.53.0/go.mod h1:JvMuJH7rrdiCfbeHoo3fCQU24Lf5JJwT9W3sJFulfgs= golang.org/x/oauth2 v0.36.0 h1:peZ/1z27fi9hUOFCAZaHyrpWG5lwe0RJEEEeH0ThlIs= golang.org/x/oauth2 v0.36.0/go.mod h1:YDBUJMTkDnJS+A4BP4eZBjCqtokkg1hODuPjwiGPO7Q= golang.org/x/sync v0.0.0-20181108010431-42b317875d0f/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM=