buildx/vendor
Sebastiaan van Stijn 7f1eaa2a8a
vendor: golang.org/x/net v0.23.0
full diff: https://github.com/golang/net/compare/v0.22.0...v0.23.0

Includes a fix for CVE-2023-45288, which is also addressed in go1.22.2
and go1.21.9;

> http2: close connections when receiving too many headers
>
> Maintaining HPACK state requires that we parse and process
> all HEADERS and CONTINUATION frames on a connection.
> When a request's headers exceed MaxHeaderBytes, we don't
> allocate memory to store the excess headers but we do
> parse them. This permits an attacker to cause an HTTP/2
> endpoint to read arbitrary amounts of data, all associated
> with a request which is going to be rejected.
>
> Set a limit on the amount of excess header frames we
> will process before closing a connection.
>
> Thanks to Bartek Nowotarski for reporting this issue.

Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
2024-04-10 17:22:06 +02:00
..
github.com Merge pull request #2392 from crazy-max/update-hcl 2024-04-10 08:48:10 +02:00
go.opentelemetry.io vendor: github.com/moby/buildkit v0.13.0-rc2 2024-02-24 17:14:01 +01:00
golang.org/x vendor: golang.org/x/net v0.23.0 2024-04-10 17:22:06 +02:00
google.golang.org vendor: github.com/moby/buildkit db304eb93126 (v0.13.0-dev) 2024-02-21 11:54:00 +01:00
gopkg.in bake: better handling of compose extension interface 2022-06-14 23:23:43 +02:00
k8s.io vendor: bump k8s dependencies to v0.29.2 2024-02-24 16:41:41 +01:00
sigs.k8s.io vendor: bump k8s dependencies to v0.29.2 2024-02-24 16:41:41 +01:00
modules.txt vendor: golang.org/x/net v0.23.0 2024-04-10 17:22:06 +02:00