deps: bump golang.org/x/net to v0.53.0 [release-4.2]

Backports the golang.org/x/net upgrade already present on main
(commit on main bumped to v0.53.0). The v0.52.0 currently pinned
in release-4.2 is affected by GO-2026-4918, a HTTP/2 vulnerability
in golang.org/x/net/http2 fixed in v0.53.0.

This affects any downstream image that ships the helm v4.2.x
binary: vulnerability scanners (Trivy, MS S360, etc.) flag the
embedded golang.org/x/net version even though helm's own code
paths may not be exploitable. A patch release on release-4.2
that includes this bump lets downstream consumers clear the
finding without waiting for v4.3.0.

Verified locally with go 1.26.3 on windows/amd64:
  go get golang.org/x/net@v0.53.0
  go mod tidy
  go build ./...   # passes

Refs: https://pkg.go.dev/vuln/GO-2026-4918
Signed-off-by: Sukhbir Singh <sukhbirsingh@microsoft.com>
pull/32131/head
Sukhbir Singh 5 months ago
parent 06468084e8
commit 02bb1602a7

@ -158,7 +158,7 @@ require (
go.opentelemetry.io/proto/otlp v1.10.0 // indirect
go.yaml.in/yaml/v2 v2.4.3 // indirect
golang.org/x/mod v0.34.0 // indirect
golang.org/x/net v0.52.0 // indirect
golang.org/x/net v0.53.0 // indirect
golang.org/x/oauth2 v0.36.0 // indirect
golang.org/x/sync v0.20.0 // indirect
golang.org/x/sys v0.43.0 // indirect

@ -400,8 +400,8 @@ golang.org/x/net v0.10.0/go.mod h1:0qNGK6F8kojg2nk9dLZ2mShWaEBan6FAoqfSigmmuDg=
golang.org/x/net v0.15.0/go.mod h1:idbUs1IY1+zTqbi8yxTbhexhEEk5ur9LInksu6HrEpk=
golang.org/x/net v0.17.0/go.mod h1:NxSsAGuq816PNPmqtQdLE42eU2Fs7NoRIZrHJAlaCOE=
golang.org/x/net v0.18.0/go.mod h1:/czyP5RqHAH4odGYxBJ1qz0+CE5WZ+2j1YgoEo8F2jQ=
golang.org/x/net v0.52.0 h1:He/TN1l0e4mmR3QqHMT2Xab3Aj3L9qjbhRm78/6jrW0=
golang.org/x/net v0.52.0/go.mod h1:R1MAz7uMZxVMualyPXb+VaqGSa3LIaUqk0eEt3w36Sw=
golang.org/x/net v0.53.0 h1:d+qAbo5L0orcWAr0a9JweQpjXF19LMXJE8Ey7hwOdUA=
golang.org/x/net v0.53.0/go.mod h1:JvMuJH7rrdiCfbeHoo3fCQU24Lf5JJwT9W3sJFulfgs=
golang.org/x/oauth2 v0.36.0 h1:peZ/1z27fi9hUOFCAZaHyrpWG5lwe0RJEEEeH0ThlIs=
golang.org/x/oauth2 v0.36.0/go.mod h1:YDBUJMTkDnJS+A4BP4eZBjCqtokkg1hODuPjwiGPO7Q=
golang.org/x/sync v0.0.0-20181108010431-42b317875d0f/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM=

Loading…
Cancel
Save