can you take a look at https://github.com/entireio/git-sync/security/dependabot/5 · Entire
Changes Summary
Fixed Alert #5
By bumping golang.org/x/net v0.54.0 → v0.55.0 (which also pulled x/sys v0.44.0 → v0.45.0). Build passes.
Changes are staged in the working tree only (go.mod + go.sum) — I haven't committed. Note we're currently on branch soph/enable-ref-backend.
Next Steps
Want me to:
- Commit this on the current branch, or a fresh branch (e.g.
soph/bump-x-net)? - Open a PR?
Also worth knowing: since x/net is only a transitive dependency and we don't touch x/net/html, there was no real exposure — this bump just clears the Dependabot alert cleanly.
Branch Creation
Done. Created branch soph/bump-x-net off soph/enable-ref-backend and committed the bump (770216b1).
Want me to push it and open a PR? If so, against which base — soph/enable-ref-backend or main?
Commit Details
eb27363
Bump golang.org/x/net to v0.55.0 to fix CVE-2026-25680
Clears Dependabot alert #5 (GHSA-5cv4-jp36-h3mw). The HTML parser in
x/net < 0.55.0 can consume excessive CPU on crafted input (CWE-400).
x/net is a transitive dependency and we don't import x/net/html, so
there was no real exposure, but this bump clears the alert cleanly.
Co-Authored-By: Claude Opus 4.8 noreply@anthropic.com
Entire-Checkpoint: 01KX17ZYX3DJPHVXPPCVNT3VTK+6/-6