upgraded golang.org/x/text v0.38.0 => v0.39.0

 % govulncheck ./...
=== Symbol Results ===

Vulnerability #1: GO-2026-5970
    Infinite loop on invalid input in golang.org/x/text
  More info: https://pkg.go.dev/vuln/GO-2026-5970

  Module: golang.org/x/text
    Found in: golang.org/x/text@v0.38.0
    Fixed in: golang.org/x/text@v0.39.0
    Example traces found:
      #1: subcmd/version/version.go:262:36: version.Command.sisoCommit calls http.Client.Do, which eventually calls norm.Form.Bytes
      #2: subcmd/version/version.go:262:36: version.Command.sisoCommit calls http.Client.Do, which eventually calls norm.Form.IsNormalString
      #3: subcmd/version/version.go:262:36: version.Command.sisoCommit calls http.Client.Do, which eventually calls norm.Form.QuickSpan
      #4: subcmd/version/version.go:262:36: version.Command.sisoCommit calls http.Client.Do, which eventually calls norm.Form.String
Change-Id: I04fc1a8719ef341c466e3437719f8a76b92a340d
Reviewed-on: https://chromium-review.googlesource.com/c/build/+/8131405
Reviewed-by: Philipp Wollermann <philwo@google.com>
Auto-Submit: Fumitoshi Ukai <ukai@google.com>
Commit-Queue: Fumitoshi Ukai <ukai@google.com>
8 files changed
tree: e6532717d6c2695dde0c5d472d09082c373eb034
  1. bench/
  2. gong/
  3. hashigo/
  4. infra/
  5. kajiya/
  6. kzipinfo/
  7. remote-apis/
  8. runmc/
  9. siso/
  10. .gitignore
  11. .golangci.yml
  12. .style.yapf
  13. BUILD_OWNERS
  14. BUILD_TEAM_OWNERS
  15. CONTRIBUTING.md
  16. LICENSE
  17. OWNERS
  18. PRESUBMIT.py
  19. README.md
  20. WATCHLISTS
README.md

build.git repository

This repository contains tools developed and owned by the Chrome Build Team.

Quick start

The steps for getting the code are:

  1. Install depot_tools
  2. Run git clone https://chromium.googlesource.com/build

We use the standard Go module workflow to work on our projects.

Links