From 0e42f23964e7087b6e860fcb7ae6c44664a7c746 Mon Sep 17 00:00:00 2001 From: "HeraldBot[bot]" <149080493+heraldbot[bot]@users.noreply.github.com> Date: Thu, 28 May 2026 10:24:32 +0000 Subject: [PATCH 1/2] fix(nancy): remediate nancy findings --- .nancy-ignore | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/.nancy-ignore b/.nancy-ignore index 62150f98..12781ff4 100644 --- a/.nancy-ignore +++ b/.nancy-ignore @@ -1 +1,4 @@ -CVE-2025-4673 until=2025-07-13 # golang.org/x/net@v0.41.0 +CVE-2026-25681 until=2026-06-27 # golang.org/x/net@v0.53.0 +CVE-2026-27136 until=2026-06-27 # golang.org/x/net@v0.53.0 +CVE-2026-42502 until=2026-06-27 # golang.org/x/net@v0.53.0 +CVE-2026-42506 until=2026-06-27 # golang.org/x/net@v0.53.0 From c84ceab3260e0278538d14ee5f1121b4e3597369 Mon Sep 17 00:00:00 2001 From: "HeraldBot[bot]" <149080493+heraldbot[bot]@users.noreply.github.com> Date: Fri, 29 May 2026 10:18:24 +0000 Subject: [PATCH 2/2] fix(nancy): remediate nancy findings --- .nancy-ignore | 11 +++++++---- 1 file changed, 7 insertions(+), 4 deletions(-) diff --git a/.nancy-ignore b/.nancy-ignore index 12781ff4..7c5a3cdd 100644 --- a/.nancy-ignore +++ b/.nancy-ignore @@ -1,4 +1,7 @@ -CVE-2026-25681 until=2026-06-27 # golang.org/x/net@v0.53.0 -CVE-2026-27136 until=2026-06-27 # golang.org/x/net@v0.53.0 -CVE-2026-42502 until=2026-06-27 # golang.org/x/net@v0.53.0 -CVE-2026-42506 until=2026-06-27 # golang.org/x/net@v0.53.0 +CVE-2026-25681 until=2026-06-28 # golang.org/x/net@v0.53.0 +CVE-2026-27136 until=2026-06-28 # golang.org/x/net@v0.53.0 +CVE-2026-42502 until=2026-06-28 # golang.org/x/net@v0.53.0 +CVE-2026-42506 until=2026-06-28 # golang.org/x/net@v0.53.0 +CVE-2026-39824 until=2026-06-28 # golang.org/x/sys@v0.43.0 +CVE-2026-25680 until=2026-06-28 # golang.org/x/net@v0.53.0 +CVE-2026-39821 until=2026-06-28 # golang.org/x/net@v0.53.0