Skip to content

docs: add security disclosure policy#31

Merged
babs merged 2 commits into
masterfrom
docs/security-policy
May 20, 2026
Merged

docs: add security disclosure policy#31
babs merged 2 commits into
masterfrom
docs/security-policy

Conversation

@babs

@babs babs commented May 20, 2026

Copy link
Copy Markdown
Owner

No description provided.

babs added 2 commits May 20, 2026 20:10
Patches stdlib CVEs reachable from current code:
- GO-2026-4982, GO-2026-4980: html/template escaper bypass XSS
  (renderConsent in handlers/consent.go)
- GO-2026-4976: net/http/httputil ReverseProxy query-param forwarding
- GO-2026-4971: net Dial NUL-byte panic (Windows)
- GO-2026-4918: net/http HTTP/2 SETTINGS_MAX_FRAME_SIZE infinite loop

Dockerfile builder digest refreshed to a 1.26-alpine image that
resolves to 1.26.3.
@babs babs force-pushed the docs/security-policy branch from b0d8ee6 to 8c61acd Compare May 20, 2026 18:15
@babs babs merged commit 04e3fe0 into master May 20, 2026
7 checks passed
@babs babs deleted the docs/security-policy branch May 26, 2026 01:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant