Skip to content

Bump github.com/txn2/txeh from 1.5.5 to 1.8.1 - #246

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/go_modules/github.com/txn2/txeh-1.8.1
Open

Bump github.com/txn2/txeh from 1.5.5 to 1.8.1#246
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/go_modules/github.com/txn2/txeh-1.8.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 1, 2026

Copy link
Copy Markdown
Contributor

Bumps github.com/txn2/txeh from 1.5.5 to 1.8.1.

Release notes

Sourced from github.com/txn2/txeh's releases.

txeh-v1.8.1

txeh v1.8.1

A maintenance release. The notable change is hardening how comments and hostnames are written to the hosts file.

Bug fixes

  • Strip line-break characters from hostnames and comments (#90). Comments and hostnames passed to AddHost / AddHostWithComment were trimmed but kept embedded \r, \n, \v, \f, and NUL characters. Since the line formatter interpolated those fields directly, an embedded \r\n could split one logical entry across multiple physical lines and corrupt the file when read back (CWE-117). These characters are now stripped both at the input boundary and at render time. Tabs, spaces, and # are preserved, so normal comments are unaffected, and the public API is unchanged.

    This addresses a reported "CRLF injection." For the record: exploiting it through the CLI requires root plus an attacker-controlled -w path, which already grants arbitrary file write without any comment trick, so the privilege-escalation framing does not hold. The real gap was data hygiene for library callers that may pass untrusted input, which is what this fixes.

Documentation

  • Adopt the txn2 design system for the docs site (#77).

Maintenance

Routine CI and dependency bumps (codeql-action, gosec, goreleaser, cosign, sbom-action, golangci-lint, setup-go, codecov, rapid). See the full commit list below.

Others

  • e6835b87e1466fd86e38a0ed0e2638c22d49c7f2 chore(ci): bump CI dependencies (#71)
  • 4a44bdb112f4ad57d196e86f6080a3661f6dd76a chore(ci): bump actions/setup-go from 6.2.0 to 6.3.0 (#54)
  • 5b2294eccb18709a25ae85e9a3d849424c17b043 chore(ci): bump actions/upload-pages-artifact from 4.0.0 to 5.0.0 (#73)
  • 22bc0a5bf7644d5a18bd81de19681415e850aaad chore(ci): bump anchore/sbom-action from 0.22.2 to 0.23.0 (#57)
  • 96f971c5cbabee7e470d53fd336704c88c991c4a chore(ci): bump anchore/sbom-action from 0.23.0 to 0.23.1 (#60)
  • fd47a7ecea468b35b159d859ff1cce3400ccf5f7 chore(ci): bump anchore/sbom-action from 0.23.1 to 0.24.0 (#65)
  • 5fedd09c28d32b47afa4140c5837e6063d7caeb4 chore(ci): bump codecov/codecov-action from 5.5.2 to 5.5.3 (#62)
  • 6ee1551f2a14419fdb81fda288d85b16de860d06 chore(ci): bump codecov/codecov-action from 6.0.0 to 6.0.1 (#86)
  • 44af6237a9fa80ea90ba074bcb160ea0876c39d5 chore(ci): bump github/codeql-action from 3.32.1 to 4.32.2 (#49)
  • a74204e34bf05cc4e19149a1848dbc4a22fcfcaf chore(ci): bump github/codeql-action from 4.32.2 to 4.32.3 (#50)
  • 35fb19049113c39162883684cdfeda21cdbdb842 chore(ci): bump github/codeql-action from 4.32.3 to 4.32.4 (#52)
  • dad96ee41d3e89d3c470d085f671775afe99679f chore(ci): bump github/codeql-action from 4.32.4 to 4.32.5 (#55)
  • e66cb5e1053e25333cb9579682a61139d1c71f70 chore(ci): bump github/codeql-action from 4.32.5 to 4.32.6 (#59)
  • cdb139f7d386d14151252fc9f8a68bab5282d7ae chore(ci): bump github/codeql-action from 4.32.6 to 4.33.0 (#61)
  • d94b163d8c9d5b340f7af28f720cc62ee7a44516 chore(ci): bump github/codeql-action from 4.33.0 to 4.34.1 (#63)
  • 49645c9a52abfe674d677a2feaf6af62f427bf67 chore(ci): bump github/codeql-action from 4.35.1 to 4.35.2 (#74)
  • 6d0d8ede565ce831efebfe82fdac2c7a3c189e76 chore(ci): bump github/codeql-action from 4.35.2 to 4.35.3 (#81)
  • c15ac928b4fca8916d81871df3d180223b3322fd chore(ci): bump github/codeql-action from 4.35.3 to 4.35.4 (#82)
  • e4fb26d01a15a2258408a375df1658ef8d5f8801 chore(ci): bump github/codeql-action from 4.35.4 to 4.35.5 (#84)
  • 879894bc4a6d6f574bb2fb98df451e696fffde30 chore(ci): bump github/codeql-action from 4.35.5 to 4.36.0 (#88)
  • d3243398ac65ad3d69d4a2e6194e4d0e6d1715d8 chore(ci): bump golangci/golangci-lint-action from 9.2.0 to 9.2.1 (#89)
  • da578acee902a376051bf7b6bcfe89162f38de21 chore(ci): bump goreleaser/goreleaser-action from 6.4.0 to 7.0.0 (#53)
  • 872853a1a6f2ef784e223c099ea5c771405a3f89 chore(ci): bump goreleaser/goreleaser-action from 7.0.0 to 7.1.0 (#75)
  • e78b0d04e0d1fd55bf4b13f51ebe1cb8414eeb1e chore(ci): bump goreleaser/goreleaser-action from 7.1.0 to 7.2.1 (#79)
  • 1c52bc7cd703ec83a574b80a88da75a4f7707436 chore(ci): bump goreleaser/goreleaser-action from 7.2.1 to 7.2.2 (#85)
  • 64d5adedacfea2831ad19210b5306e526abc64af chore(ci): bump securego/gosec from 2.22.11 to 2.23.0 (#51)
  • d5fbd59b6cc6d2b5333889234ae481797d7be0cd chore(ci): bump securego/gosec from 2.23.0 to 2.24.7 (#56)

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [github.com/txn2/txeh](https://github.com/txn2/txeh) from 1.5.5 to 1.8.1.
- [Release notes](https://github.com/txn2/txeh/releases)
- [Commits](https://github.com/txn2/txeh/commits/v1.8.1)

---
updated-dependencies:
- dependency-name: github.com/txn2/txeh
  dependency-version: 1.8.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update Go code labels Jun 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update Go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants