All versions of the `resty` package are affected by [GO-2023-2328](https://pkg.go.dev/vuln/GO-2023-2328) with no available fix. I'm not familiar with the `resty` package but I'm sure it could be swapped out for `net/http`. I'm happy to submit a PR to make the change.