Skip to content

fix: upgrade golang.org/x/net v0.17.0 for http2 zero-day #937

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed

Conversation

genslein
Copy link

@genslein genslein commented Oct 12, 2023

Greetings all,

We're trying to help patch the http2 zero-day exploit and would ask a patch release be made to the exporter.

https://security.snyk.io/vuln/SNYK-GOLANG-GOLANGORGXNETHTTP2-5953327

Related dependabot change #936

Please feel free to make changes but prioritize the security fix.

Signed-off-by: Gabe Enslein <[email protected]>
Signed-off-by: Gabriel Enslein <[email protected]>
@SuperQ
Copy link
Contributor

SuperQ commented Oct 16, 2023

Fixed by dependabot. #936

@SuperQ SuperQ closed this Oct 16, 2023
@genslein genslein deleted the fix/http2-zero-day branch October 16, 2023 14:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants