autoscaler icon indicating copy to clipboard operation
autoscaler copied to clipboard

fix(deps): update module github.com/hashicorp/go-getter to v1.7.9 [security]

Open renovate-bot opened this issue 3 months ago • 1 comments

This PR contains the following updates:

Package Change Age Confidence
github.com/hashicorp/go-getter v1.7.6 -> v1.7.9 age confidence
github.com/hashicorp/go-getter v1.7.5 -> v1.7.9 age confidence

GitHub Vulnerability Alerts

CVE-2025-8959

HashiCorp's go-getter library subdirectory download feature is vulnerable to symlink attacks leading to unauthorized read access beyond the designated directory boundaries. This vulnerability, identified as CVE-2025-8959, is fixed in go-getter 1.7.9.


Release Notes

hashicorp/go-getter (github.com/hashicorp/go-getter)

v1.7.9

Compare Source

What's Changed

New Contributors

Full Changelog: https://github.com/hashicorp/go-getter/compare/v1.7.8...v1.7.9

v1.7.8

Compare Source

What's Changed

Full Changelog: https://github.com/hashicorp/go-getter/compare/v1.7.7...v1.7.8

v1.7.7

Compare Source

What's Changed

New Contributors

Full Changelog: https://github.com/hashicorp/go-getter/compare/v1.7.6...v1.7.7


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about these updates again.


  • [ ] If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

renovate-bot avatar Aug 19 '25 18:08 renovate-bot