Skip to content

chore(deps): bump golang.org/x/text from 0.37.0 to 0.39.0 - #9798

Merged
matthewmcneely merged 1 commit into
mainfrom
deps/x-text-0.39.0
Jul 29, 2026
Merged

matthewmcneely merged 1 commit into
mainfrom
deps/x-text-0.39.0

Conversation

@matthewmcneely

@matthewmcneely matthewmcneely commented Jul 29, 2026 •

Copy link
Copy Markdown
Contributor

Description

This PR bumps golang.org/x/text from 0.37.0 to 0.39.0 to fix GO-2026-5970, an infinite loop on invalid input in the normalization code. govulncheck reports the vulnerable symbols as reachable in the shipped binary through two user-facing paths: language-aware sorting (types.SortWithFacet via collate.New) and fulltext stopword filtering (tok.filterStopwords via the unicode normalize filter). Both operate on user-supplied data, so a crafted input could pin a goroutine at 100% CPU.

The go get also lifts the rest of the golang.org/x family through minimum version selection (x/net 0.56.0, x/crypto 0.53.0, x/sys, x/mod, x/sync, x/term, x/tools). The x/net bump incidentally clears the module-level GO-2026-5942 finding as well.

Verified with go test ./types/... ./tok/... (the packages on the reachable paths).


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

Fixes GO-2026-5970 (infinite loop on invalid input in x/text), which
govulncheck reports as reachable from language-aware sorting
(types.SortWithFacet) and fulltext stopword filtering. Lifts the rest
of the golang.org/x family as MVS side effects, including x/net 0.56.0
(clears module-level GO-2026-5942).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@matthewmcneely
matthewmcneely requested a review from a team as a code owner July 29, 2026 19:12
@blacksmith-sh

This comment has been minimized.

@matthewmcneely
matthewmcneely merged commit b7b1124 into main Jul 29, 2026
20 of 21 checks passed
@matthewmcneely
matthewmcneely deleted the deps/x-text-0.39.0 branch July 29, 2026 21:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

1 participant