Bump golang.org/x/net to v0.55.0 to fix CVE-2026-25680

main

Commit

Soph1mo ago

Clears Dependabot alert #5 (GHSA-5cv4-jp36-h3mw). The HTML parser in x/net < 0.55.0 can consume excessive CPU on crafted input (CWE-400). x/net is a transitive dependency and we don't import x/net/html, so there was no real exposure, but this bump clears the alert cleanly.

Co-Authored-By: Claude Opus 4.8 (1M context) noreply@anthropic.com Entire-Checkpoint: 01KX17ZYX3DJPHVXPPCVNT3VTK

Checkpoints

can you take a look at https://github.com/entireio/git-sync/security/dependabot/5

Claude CodeOpus 4.8[1m]
View session
Checkpoint 1