diff --git a/.jules/sentinel.md b/.jules/sentinel.md new file mode 100644 index 000000000..9cf39c416 --- /dev/null +++ b/.jules/sentinel.md @@ -0,0 +1,4 @@ +## 2026-08-15 - Excessive memory allocation during VP8L decoding in golang.org/x/image +**Vulnerability:** The `golang.org/x/image` package (specifically `v0.44.0`) is vulnerable to excessive memory allocation during VP8L decoding (`GO-2026-6222`). This could be exploited by providing a specially crafted image to trigger a denial of service. +**Learning:** Outdated dependencies with known CVEs pose a significant security risk, especially when processing external inputs like images in `terminalpet.decodeImage`. +**Prevention:** Regularly scan dependencies with `make vulncheck` (which runs `govulncheck`) in CI and locally. Promptly update vulnerable dependencies (e.g., `go get golang.org/x/image@v0.45.0`) to secure versions. diff --git a/go.mod b/go.mod index eb01e4a7f..47e9c2894 100644 --- a/go.mod +++ b/go.mod @@ -16,7 +16,7 @@ require ( github.com/charmbracelet/x/term v0.2.2 github.com/coder/websocket v1.8.15 github.com/ledongthuc/pdf v0.0.0-20250511090121-5959a4027728 - golang.org/x/image v0.44.0 + golang.org/x/image v0.45.0 golang.org/x/sys v0.47.0 mvdan.cc/sh/v3 v3.13.1 ) diff --git a/go.sum b/go.sum index 745a1a09f..f32f72208 100644 --- a/go.sum +++ b/go.sum @@ -64,8 +64,8 @@ github.com/xo/terminfo v0.0.0-20220910002029-abceb7e1c41e h1:JVG44RsyaB9T2KIHavM github.com/xo/terminfo v0.0.0-20220910002029-abceb7e1c41e/go.mod h1:RbqR21r5mrJuqunuUZ/Dhy/avygyECGrLceyNeo4LiM= golang.org/x/exp v0.0.0-20260611194520-c48552f49976 h1:X8Hz2ImujgbmetVuW+w2YkyZChE3cBpZi2P158rTG9M= golang.org/x/exp v0.0.0-20260611194520-c48552f49976/go.mod h1:vnf4pv9iKZXY58sQE1L86zmNWJ4159e1RkcWiLCkeEY= -golang.org/x/image v0.44.0 h1:+tDekMZED9+LrtB3G5xzRggpVh9CARjZqROla3R3R+I= -golang.org/x/image v0.44.0/go.mod h1:V8K3KE9KKKE+pLpQDOeN18w9oacNSvy1tDOirTu4xtY= +golang.org/x/image v0.45.0 h1:FMb1nTbH5H9vF55SriQHgFw5GnNL9Jg6L25BwXKzhB0= +golang.org/x/image v0.45.0/go.mod h1:n62x/7RqlwXDvGsSU4u6IUTUf6KghUZ9Bt7cG/T9Fx4= golang.org/x/sync v0.22.0 h1:SZjpbeLmrCk4xhRSZFNZW5gFUeCeFgjekvI/+gfScek= golang.org/x/sync v0.22.0/go.mod h1:9xrNwdLfx4jkKbNva9FpL6vEN7evnE43NNNJQ2LF3+0= golang.org/x/sys v0.47.0 h1:o7XGOvZQCADBQQ4Y7VNq2dRWQR7JmOUW8Kxx4ZsNgWs=