Skip to content
This repository has been archived by the owner on Apr 8, 2024. It is now read-only.

chore: update module golang.org/x/image to v0.10.0 [security] - autoclosed #478

Closed
wants to merge 1 commit into from

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Nov 6, 2023

Mend Renovate

This PR contains the following updates:

Package Type Update Change
golang.org/x/image indirect minor v0.6.0 -> v0.10.0

GitHub Vulnerability Alerts

CVE-2023-29407

A maliciously-crafted image can cause excessive CPU consumption in decoding. A tiled image with a height of 0 and a very large width can cause excessive CPU consumption, despite the image size (width * height) appearing to be zero.

CVE-2023-29408

The TIFF decoder does not place a limit on the size of compressed tile data. A maliciously-crafted image can exploit this to cause a small image (both in terms of pixel width/height, and encoded size) to make the decoder decode large amounts of compressed data, consuming excessive memory and CPU.


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate. View repository job log here.

@renovate renovate bot added the security label Nov 6, 2023
@github-actions github-actions bot added the server label Nov 6, 2023
@renovate renovate bot force-pushed the renovate/go-golang.org/x/image-vulnerability branch 4 times, most recently from 967e3cd to 2d3d1c9 Compare November 14, 2023 08:24
@renovate renovate bot force-pushed the renovate/go-golang.org/x/image-vulnerability branch 11 times, most recently from a1cb365 to 12036e4 Compare November 22, 2023 07:22
@renovate renovate bot force-pushed the renovate/go-golang.org/x/image-vulnerability branch 4 times, most recently from fe1e16a to de8638f Compare November 28, 2023 05:53
@renovate renovate bot force-pushed the renovate/go-golang.org/x/image-vulnerability branch 5 times, most recently from bae170e to 20cea62 Compare December 6, 2023 06:55
@renovate renovate bot force-pushed the renovate/go-golang.org/x/image-vulnerability branch 4 times, most recently from c058cd3 to a2b6af8 Compare December 6, 2023 12:05
@renovate renovate bot force-pushed the renovate/go-golang.org/x/image-vulnerability branch 3 times, most recently from 195cb3a to caacccf Compare December 7, 2023 06:22
@renovate renovate bot force-pushed the renovate/go-golang.org/x/image-vulnerability branch from caacccf to c5238b9 Compare December 7, 2023 13:54
@renovate renovate bot changed the title chore: update module golang.org/x/image to v0.10.0 [security] chore: update module golang.org/x/image to v0.10.0 [security] - autoclosed Dec 7, 2023
@renovate renovate bot closed this Dec 7, 2023
@renovate renovate bot deleted the renovate/go-golang.org/x/image-vulnerability branch December 7, 2023 13:58
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants