Skip to content

x/crypto: Update golang.org/x/text to 0.3.7 #51216

@ristomcgehee

Description

@ristomcgehee

x/crypto is currently using version 0.3.6 of golang.org/x/text which has a denial of service vulnerability: https://osv.dev/vulnerability/GO-2021-0113.

I would like to request that x/crypto updates its modules to use version 0.3.7 or higher of golang.org/x/text. Alternatively, if you're confident that x/crypto does not call the vulnerable functions, go ahead and close this issue.

Metadata

Metadata

Assignees

No one assigned

    Labels

    FrozenDueToAgeNeedsInvestigationSomeone must examine and confirm this is a valid issue and not a duplicate of an existing one.

    Type

    No type

    Projects

    No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions