Skip to content

Update dependencies#26

Open
grisu48 wants to merge 1 commit into
eliukblau:masterfrom
grisu48:deps
Open

Update dependencies#26
grisu48 wants to merge 1 commit into
eliukblau:masterfrom
grisu48:deps

Conversation

@grisu48
Copy link
Copy Markdown

@grisu48 grisu48 commented Apr 9, 2026

Update dependencies to fix CVE-2026-33809

This repository uses an outdated version of golang.org/x/image which is vulnerable to excessive resource consumption or an out-of-memory error (See https://pkg.go.dev/vuln/GO-2026-4815). The issue is patched in golang.org/x/image from version 0.38 onwards.

This Pull Requests updates all dependencies to the most recent version. I tested the new binary locally against the images in docs/images and the output seemed fine.

Update dependencies to fix CVE-2026-33809.
@eliukblau
Copy link
Copy Markdown
Owner

@grisu48 Thanks for contributing! I'll look into this and do the merge as soon as possible. I've been very busy lately.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants