From 35721769c7298c83e3f3714f9f55e5d056bd0729 Mon Sep 17 00:00:00 2001 From: D Date: Tue, 7 Mar 2023 11:06:37 +0000 Subject: [PATCH] Retract v1.0.22 and prior due to old x/net dependency Old dependency of x/net was vulnerable to CVE-2022-41723 and required an update, v1.0.23 of bluemonday has the update and we retract the old versions --- go.mod | 4 +--- 1 file changed, 1 insertion(+), 3 deletions(-) diff --git a/go.mod b/go.mod index d121174..41b51ce 100644 --- a/go.mod +++ b/go.mod @@ -9,6 +9,4 @@ require ( require github.com/gorilla/css v1.0.0 // indirect -retract [v1.0.0, v1.0.18] // Retract older versions as only latest is to be depended upon - -retract v1.0.19 // Uses older version of golang.org/x/net +retract [v1.0.0, v1.0.22] // Retract older versions as only latest is to be depended upon