Skip to content

Conversation

@elliotcourant
Copy link
Collaborator

No description provided.

@elliotcourant elliotcourant marked this pull request as ready for review November 26, 2025 01:51
@elliotcourant
Copy link
Collaborator Author

This is a bit of a hack however, instead of bumping all of the (basically stable) dependencies that go-pg is using. It seems better to just bump the transitive dependency that is the /x/... packages as they don't usually have breaking changes and as long as tests pass should continue to work just fine.

This way the security alert is properly resolved and any others that came with any of the /x/... dependencies.

@elliotcourant elliotcourant merged commit 2630433 into v10 Nov 26, 2025
2 checks passed
@elliotcourant elliotcourant deleted the fix/crypto-security branch November 26, 2025 01:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants