chore(deps): update module golang.org/x/text to v0.39.0 [security] #79

Merged
renovate-bot merged 1 commits from renovate/go-golang.org-x-text-vulnerability into main 2026-07-22 15:44:25 +02:00
Collaborator

This PR contains the following updates:

Package Change Age Confidence
golang.org/x/text v0.38.0v0.39.0 age confidence

Infinite loop on invalid input in golang.org/x/text

CVE-2026-56852 / GO-2026-5970

More information

Details

A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes.

Severity

Unknown

References

This data is provided by OSV and the Go Vulnerability Database (CC-BY 4.0).


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate.

This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [golang.org/x/text](https://pkg.go.dev/golang.org/x/text) | [`v0.38.0` → `v0.39.0`](https://cs.opensource.google/go/x/text/+/refs/tags/v0.38.0...refs/tags/v0.39.0) | ![age](https://developer.mend.io/api/mc/badges/age/go/golang.org%2fx%2ftext/v0.39.0?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/go/golang.org%2fx%2ftext/v0.38.0/v0.39.0?slim=true) | --- ### Infinite loop on invalid input in golang.org/x/text [CVE-2026-56852](https://nvd.nist.gov/vuln/detail/CVE-2026-56852) / [GO-2026-5970](https://pkg.go.dev/vuln/GO-2026-5970) <details> <summary>More information</summary> #### Details A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes. #### Severity Unknown #### References - [https://go.dev/issue/80142](https://go.dev/issue/80142) - [https://go.dev/cl/794100](https://go.dev/cl/794100) This data is provided by [OSV](https://osv.dev/vulnerability/GO-2026-5970) and the [Go Vulnerability Database](https://github.com/golang/vulndb) ([CC-BY 4.0](https://github.com/golang/vulndb#license)). </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yNjMuOSIsInVwZGF0ZWRJblZlciI6IjQzLjI2My45IiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJhdXRvbWVyZ2UiLCJzZWN1cml0eSJdfQ==-->
renovate-bot added the automergesecurity labels 2026-07-22 06:10:41 +02:00
renovate-bot scheduled this pull request to auto merge when all checks succeed 2026-07-22 06:10:41 +02:00
renovate-bot added 1 commit 2026-07-22 15:43:20 +02:00
renovate-bot force-pushed renovate/go-golang.org-x-text-vulnerability from 999c8116c1 to d840f2ac99 2026-07-22 15:43:20 +02:00 Compare
renovate-bot merged commit 0b35a4e933 into main 2026-07-22 15:44:25 +02:00
renovate-bot deleted branch renovate/go-golang.org-x-text-vulnerability 2026-07-22 15:44:25 +02:00
Sign in to join this conversation.
No Reviewers
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: t.behrendt/tracebasedlogsampler#79