Aditya Oza
07/06/2026, 3:54 PM<http://golang.org/x/net|golang.org/x/net>
⢠Current (v4.88.0): v0.53.0 ā Fix: v0.55.0
š“ CVE-2026-39832 (Critical)
⢠Package: <http://golang.org/x/crypto|golang.org/x/crypto>
⢠Current (v4.88.0): v0.50.0 ā Fix: v0.52.0
š CVE-2023-32698 (High)
⢠Package: <http://github.com/goreleaser/nfpm/v2|github.com/goreleaser/nfpm/v2>
⢠Current (v4.88.0): v2.20.0 ā Fix: v2.29.0
I noticed that main already has the fixed versions for <http://golang.org/x/net|golang.org/x/net> (v0.55.0) and <http://golang.org/x/crypto|golang.org/x/crypto> (v0.52.0) ā looks like those have been merged for about 2 weeks now in your main branch. However, the latest releases (v4.87.0, v4.88.0) don't seem to include them.
Could you let us know:
1. Which upcoming release will include these dependency bumps?
2. Is there a timeline for bumping goreleaser/nfpm/v2 from v2.20.0 to v2.29.0 to address CVE-2023-32698?
These are hitting our vulnerability SLO so any visibility into release timing would be really helpful.Lucas Rodriguez
07/06/2026, 5:04 PM2. Is there a timeline for bumpingIt's a CVE in a fleetctl dependency, not the fleet server. See github.com/fleetdm/fleet/blob/ā¦/status.md?plain=1#⦠for the exclusion from the fleetdm/fleet server image. And the exclusion from the fleetctl binary itself: github.com/fleetdm/fleet/blob/ā¦/status.md?plain=1#ā¦.from v2.20.0 to v2.29.0 to address CVE-2023-32698?goreleaser/nfpm/v2