Skip to content

Update module golang.org/x/oauth2 to v0.27.0 [SECURITY] - #105

Open
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/go-golang.org-x-oauth2-vulnerability
Open

Update module golang.org/x/oauth2 to v0.27.0 [SECURITY]#105
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/go-golang.org-x-oauth2-vulnerability

Conversation

@renovate

@renovate renovate Bot commented Jul 28, 2025

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
golang.org/x/oauth2 v0.7.0v0.27.0 age adoption passing confidence

GitHub Vulnerability Alerts

CVE-2025-22868

An attacker can pass a malicious malformed token which causes unexpected memory to be consumed during parsing.

Severity
  • CVSS Score: 7.5 / 10 (High)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • ""
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Never, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the security label Jul 28, 2025
@renovate

renovate Bot commented Jul 28, 2025

Copy link
Copy Markdown
Contributor Author

ℹ Artifact update notice

File name: go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 1 additional dependency was updated
  • The go directive was updated for compatibility reasons

Details:

Package Change
go 1.21 -> 1.23.0
cloud.google.com/go/compute/metadata v0.2.3 -> v0.3.0

@trapacska

Copy link
Copy Markdown
Contributor

View build log

@renovate renovate Bot changed the title Update module golang.org/x/oauth2 to v0.27.0 [SECURITY] Update module golang.org/x/oauth2 to v0.27.0 [SECURITY] - autoclosed Dec 24, 2025
@renovate renovate Bot closed this Dec 24, 2025
@renovate
renovate Bot deleted the renovate/go-golang.org-x-oauth2-vulnerability branch December 24, 2025 05:41
@renovate renovate Bot changed the title Update module golang.org/x/oauth2 to v0.27.0 [SECURITY] - autoclosed Update module golang.org/x/oauth2 to v0.27.0 [SECURITY] Dec 24, 2025
@renovate renovate Bot reopened this Dec 24, 2025
@renovate
renovate Bot force-pushed the renovate/go-golang.org-x-oauth2-vulnerability branch 2 times, most recently from 6545526 to 6b22c8a Compare December 24, 2025 08:59
@renovate

renovate Bot commented Dec 24, 2025

Copy link
Copy Markdown
Contributor Author

ℹ️ Artifact update notice

File name: go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 1 additional dependency was updated
  • The go directive was updated for compatibility reasons

Details:

Package Change
go 1.21 -> 1.23.0
cloud.google.com/go/compute/metadata v0.2.3 -> v0.3.0

@renovate renovate Bot changed the title Update module golang.org/x/oauth2 to v0.27.0 [SECURITY] Update module golang.org/x/oauth2 to v0.27.0 [SECURITY] - autoclosed Feb 10, 2026
@renovate renovate Bot closed this Feb 10, 2026
@renovate renovate Bot changed the title Update module golang.org/x/oauth2 to v0.27.0 [SECURITY] - autoclosed Update module golang.org/x/oauth2 to v0.27.0 [SECURITY] Feb 10, 2026
@renovate renovate Bot reopened this Feb 10, 2026
@renovate
renovate Bot force-pushed the renovate/go-golang.org-x-oauth2-vulnerability branch 2 times, most recently from 6b22c8a to 1282f31 Compare February 10, 2026 09:09
@renovate renovate Bot changed the title Update module golang.org/x/oauth2 to v0.27.0 [SECURITY] Update module golang.org/x/oauth2 to v0.27.0 [SECURITY] - autoclosed Mar 27, 2026
@renovate renovate Bot closed this Mar 27, 2026
@renovate renovate Bot changed the title Update module golang.org/x/oauth2 to v0.27.0 [SECURITY] - autoclosed Update module golang.org/x/oauth2 to v0.27.0 [SECURITY] Apr 1, 2026
@renovate renovate Bot reopened this Apr 1, 2026
@renovate
renovate Bot force-pushed the renovate/go-golang.org-x-oauth2-vulnerability branch 2 times, most recently from 1282f31 to 58ae486 Compare April 1, 2026 17:07
@renovate renovate Bot changed the title Update module golang.org/x/oauth2 to v0.27.0 [SECURITY] Update module golang.org/x/oauth2 to v0.27.0 [SECURITY] - autoclosed Apr 15, 2026
@renovate renovate Bot closed this Apr 15, 2026
@renovate renovate Bot changed the title Update module golang.org/x/oauth2 to v0.27.0 [SECURITY] - autoclosed Update module golang.org/x/oauth2 to v0.27.0 [SECURITY] Apr 16, 2026
@renovate renovate Bot reopened this Apr 16, 2026
@renovate
renovate Bot force-pushed the renovate/go-golang.org-x-oauth2-vulnerability branch 2 times, most recently from 58ae486 to 6739a34 Compare April 16, 2026 16:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant