Skip to content

chore(deps): bump golang.org/x/image from 0.25.0 to 0.38.0#20

Open
dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/go_modules/golang.org/x/image-0.38.0
Open

chore(deps): bump golang.org/x/image from 0.25.0 to 0.38.0#20
dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/go_modules/golang.org/x/image-0.38.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Mar 30, 2026

Copy link
Copy Markdown

Bumps golang.org/x/image from 0.25.0 to 0.38.0.

Commits
  • 23ae9ed tiff: cap buffer growth to prevent OOM from malicious IFD offset
  • e589e60 webp: allow VP8L + VP8X(with alpha)
  • fe7d73d go.mod: update golang.org/x dependencies
  • e3d762b all: upgrade go directive to at least 1.25.0 [generated]
  • 833c6ed go.mod: update golang.org/x dependencies
  • bc7fe0b go.mod: update golang.org/x dependencies
  • c53c97f go.mod: update golang.org/x dependencies
  • 9032ff7 all: eliminate vet diagnostics
  • 9c9d08c go.mod: update golang.org/x dependencies
  • 742b1b7 all: fix some comments
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels Mar 30, 2026
iulian-taraboanta pushed a commit that referenced this pull request Apr 16, 2026
…um-optimism#19273)

* chore(contracts): add initializer side-effects review rules

Add AI review rules for detecting initializer functions with
side-effects (loops, mapping writes, external calls) that could
be unsafe during contract re-initialization with partial state.

Addresses audit finding #20 (ETHLockbox re-initialization footgun).

Co-Authored-By: Claude Opus 4.6 <[email protected]>

* Update docs/ai/contract-dev.md

Co-authored-by: Maurelian <[email protected]>

* Update docs/ai/contract-dev.md

Co-authored-by: graphite-app[bot] <96075541+graphite-app[bot]@users.noreply.github.com>

---------

Co-authored-by: Claude Opus 4.6 <[email protected]>
Co-authored-by: Maurelian <[email protected]>
Co-authored-by: graphite-app[bot] <96075541+graphite-app[bot]@users.noreply.github.com>
Bumps [golang.org/x/image](https://github.com/golang/image) from 0.25.0 to 0.38.0.
- [Commits](golang/image@v0.25.0...v0.38.0)

---
updated-dependencies:
- dependency-name: golang.org/x/image
  dependency-version: 0.38.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot Bot force-pushed the dependabot/go_modules/golang.org/x/image-0.38.0 branch from 9793d3f to 77b50b7 Compare April 16, 2026 12:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants