Skip to content

fix(chi): CVE GO-2025-3770#16

Open
thejoeejoee wants to merge 1 commit intoThreeDotsLabs:masterfrom
thejoeejoee:master
Open

fix(chi): CVE GO-2025-3770#16
thejoeejoee wants to merge 1 commit intoThreeDotsLabs:masterfrom
thejoeejoee:master

Conversation

@thejoeejoee
Copy link
Contributor

@thejoeejoee thejoeejoee commented Sep 3, 2025

Motivation / Background

get rid of CVE https://pkg.go.dev/vuln/GO-2025-3770

Details

Alternative approaches considered (if applicable)

Checklist

The resources of our team are limited. There are a couple of things that you can do to help us merge your PR faster:

  • I wrote tests for the changes.
  • All tests are passing.
    • If you are testing a Pub/Sub, you can start Docker with make up.
    • You can start with make test_short for a quick check.
    • If you want to run all tests, use make test.
  • Code has no breaking changes.
  • (If applicable) documentation on watermill.io is updated.

@thejoeejoee thejoeejoee closed this Sep 3, 2025
@thejoeejoee thejoeejoee reopened this Sep 3, 2025
@thejoeejoee thejoeejoee changed the title chore(deps): bump chi fix(chi): CVE GO-2025-3770 Sep 3, 2025
@thejoeejoee thejoeejoee marked this pull request as ready for review September 4, 2025 11:55
"sync"

"github.com/go-chi/chi"
"github.com/go-chi/chi/v5"
Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hi can you also update the import in pkg/http/sse_test.go so that we get rid of the v4 import entirely?

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

fixed

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@laouji would you mind to do a CR? thanks

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants