Commit 8782002
authored
fix(go.mod): upgrade goldmark to v1.7.17 (CVE-2026-5160) (#25252)
## Summary
Upgrades `github.com/yuin/goldmark` from v1.7.13 to v1.7.17 on the
`release/2.29` branch to remediate **CVE-2026-5160** (XSS via improper
ordering of URL validation and normalization).
## Changes
- `go.mod`: bump `github.com/yuin/goldmark` v1.7.13 → v1.7.17
- `go.sum`: updated checksums
## References
- [CVE-2026-5160 (NVD)](https://nvd.nist.gov/vuln/detail/CVE-2026-5160)
- Fix on main: #23957
- Linear: ENT-41
> [!NOTE]
> Generated by Coder Agents. Please review before merging.1 parent c67fe2c commit 8782002
2 files changed
Lines changed: 3 additions & 3 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
424 | 424 | | |
425 | 425 | | |
426 | 426 | | |
427 | | - | |
| 427 | + | |
428 | 428 | | |
429 | 429 | | |
430 | 430 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1190 | 1190 | | |
1191 | 1191 | | |
1192 | 1192 | | |
1193 | | - | |
1194 | | - | |
| 1193 | + | |
| 1194 | + | |
1195 | 1195 | | |
1196 | 1196 | | |
1197 | 1197 | | |
| |||
0 commit comments