Update module github.com/go-git/go-git/v5 to v5.17.1 [SECURITY]#2668
Update module github.com/go-git/go-git/v5 to v5.17.1 [SECURITY]#2668pulumi-renovate[bot] merged 1 commit intomasterfrom
Conversation
ℹ Artifact update noticeFile name: aws-apigateway-go-routes/go.modIn order to perform the update(s) described in the table above, Renovate ran the
Details:
File name: aws-go-ansible-wordpress/go.modIn order to perform the update(s) described in the table above, Renovate ran the
Details:
File name: misc/benchmarks/go-many-resources/go.modIn order to perform the update(s) described in the table above, Renovate ran the
Details:
File name: misc/test/go.modIn order to perform the update(s) described in the table above, Renovate ran the
Details:
File name: stack-readme-go/go.modIn order to perform the update(s) described in the table above, Renovate ran the
Details:
File name: testing-integration/go.modIn order to perform the update(s) described in the table above, Renovate ran the
Details:
|
This PR contains the following updates:
v5.16.5->v5.17.1GitHub Vulnerability Alerts
CVE-2026-33762
Impact
go-git’s index decoder for format version 4 fails to validate the path name prefix length before applying it to the previously decoded path name. A maliciously crafted index file can trigger an out-of-bounds slice operation, resulting in a runtime panic during normal index parsing.This issue only affects Git index format version 4. Earlier formats (
go-gitsupports onlyv2andv3) are not vulnerable to this issue.An attacker able to supply a crafted
.git/indexfile can cause applications using go-git to panic while reading the index. If the application does not recover from panics, this results in process termination, leading to a denial-of-service (DoS) condition.Exploitation requires the ability to modify or inject a Git index file within the local repository in disk. This typically implies write access to the
.gitdirectory.Patches
Users should upgrade to
v5.17.1, or the latestv6pseudo-version, in order to mitigate this vulnerability.Credit
go-git maintainers thank @kq5y for finding and reporting this issue privately to the
go-gitproject.Release Notes
go-git/go-git (github.com/go-git/go-git/v5)
v5.17.1Compare Source
What's Changed
Full Changelog: go-git/go-git@v5.17.0...v5.17.1
v5.17.0Compare Source
What's Changed
Full Changelog: go-git/go-git@v5.16.5...v5.17.0
Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - Monday through Friday ( * * * * 1-5 ) (UTC).
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Renovate Bot.