Skip to content

Conversation

@datalogics-jacksonm
Copy link
Contributor

@datalogics-jacksonm datalogics-jacksonm commented Nov 4, 2025

  • Ran go mod tidy, bumped base Go version from 1.23.0 -> 1.24.0
  • Bump Go from 1.24.0 -> 1.25.3
  • Bump golang.org/x/net from v0.43.0 -> v0.46.0
  • Bump golang.org/x/sys from v0.35.0 -> v0.37.0

Should address CVE-2025-58187.

Docker Scout is reporting tons of high severity vulnerabilities, even though html-to-markdown doesn't really touch the affected code (to the best of my knowledge). Unfortunately, Docker Scout doesn't really care...

I ran the tests locally and didn't see any regressions.

@datalogics-jacksonm datalogics-jacksonm changed the title Bump Go from v1.24.0 -> v1.25.0 Bump Go from v1.24.0 -> v1.25.2 Nov 4, 2025
@datalogics-jacksonm datalogics-jacksonm changed the title Bump Go from v1.24.0 -> v1.25.2 Bump Go from v1.24.0 -> v1.25.3 Nov 4, 2025
- use v1.25.3 for toolchain
this was automatic behavior from running `go mod tidy`.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant