Skip to content

fix(deps): golang.org/x/image v0.45.0 for GO-2026-6222 - #14

Merged
Sulaiman-Dauda merged 1 commit into
mainfrom
fix/x-image-go-2026-6222
Oct 3, 2026
Merged

Sulaiman-Dauda merged 1 commit into
mainfrom
fix/x-image-go-2026-6222

Conversation

@Sulaiman-Dauda

Copy link
Copy Markdown
Owner

govulncheck in CI started failing on GO-2026-6222 (excessive memory allocation during VP8L decoding in golang.org/x/image), and the call is reachable: storage.ImageProcessor.GetImageDimensions calls image.DecodeConfig on uploaded files, so a crafted image could exhaust memory.

Bumps golang.org/x/image to v0.45.0, the fixed release; it also requires x/sys v0.47.0 and x/text v0.41.0. No code changes.

Verified locally: go build, go vet and the full go test suite pass, and govulncheck reports 0 vulnerabilities affecting this code (1 before). This unblocks #13.

🤖 Generated with Claude Code

govulncheck flagged GO-2026-6222, excessive memory allocation in VP8L
decoding, as reachable: storage.ImageProcessor.GetImageDimensions calls
image.DecodeConfig on uploaded files. Fixed upstream in v0.45.0, which also
requires x/sys v0.47.0 and x/text v0.41.0.

Verified locally: go build, go vet and go test ./... pass, and govulncheck
reports 0 vulnerabilities affecting this code (1 before).

Co-Authored-By: Claude Opus 5.5 <[email protected]>
@Sulaiman-Dauda
Sulaiman-Dauda merged commit 1f3197b into main Oct 3, 2026
2 checks passed
@Sulaiman-Dauda
Sulaiman-Dauda deleted the fix/x-image-go-2026-6222 branch October 3, 2026 20:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant