fix(deps): update module github.com/labstack/echo/v4 to v4.16.0 - #66
Open
renovate[bot] wants to merge 1 commit into
Open
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
v4.15.4→v4.16.0Release Notes
labstack/echo (github.com/labstack/echo/v4)
v4.16.0Compare Source
Security
This release fixes several security issues. Upgrading is recommended. Some fixes change behavior; read "Behavior changes to check before upgrading" below.
Context.Scheme()now uses theX-Forwarded-Proto,X-Forwarded-Protocol,X-Forwarded-SslandX-Url-Schemeheaders only when the request comes directly from a loopback, link-local or private network address or a unix socket. Before this, any client could sendX-Forwarded-Proto: httpsover plain HTTP and skipHTTPSRedirect. WhenX-Forwarded-Protois present, only it is used (its last value), and the scheme is returned in lowercase. the newEcho#SchemeExtractorfield selects the strategy:ExtractSchemeFromHeaders(...TrustOption)(default),ExtractSchemeDirect()orLegacySchemeExtractor(). The Secure middleware now sets HSTS based onContext.Scheme(). The Proxy middleware always setsX-Forwarded-ProtofromContext.Scheme()and removesX-Forwarded-Ssl,X-Forwarded-ProtocolandX-Url-Schemebefore forwarding. GHSA-2ffq-g2xg-c22pContext.JSONPandContext.JSONPBlobaccept only a callback that is empty, a JavaScript identifier or a dot-separated path of identifiers (ASCII letters, digits,_and$). Any other callback returns a 400 Bad Request error that wraps the newErrInvalidJSONPCallback, and nothing is written. JSONP responses now carryX-Content-Type-Options: nosniff. JSONP lets any website read the response with the user's cookies, so do not use it for data that needs authentication. GHSA-h9g5-28mm-hx3gGET,HEAD,OPTIONS,TRACEorCONNECT. Before this, with theMethodFromFormorMethodFromQuerygetter and MethodOverride registered withUsebefore the CSRF middleware,_method=GETskipped the CSRF check. Register MethodOverride withEcho#Pre. GHSA-r7w9-592q-9vg4/%09/evil.example/redirected browsers toevil.example. GHSA-v753-g4cw-jm48/admin%2Fsecret.txtor/%61dmin/secret.txtcan no longer reach a file under a guarded/admin/*route. GHSA-375p-5qhx-8wq4 The Static middleware andStaticDirectoryHandler(used byEcho.Static,Echo.StaticFS,Group.StaticandGroup.StaticFS) no longer serve paths with a.,..or empty segment, such as/assets/../admin/secret.txt, also after path unescaping. GHSA-3pmx-cf9f-34xrgolang.org/x/textto v0.40.0 (GO-2026-5970).Client IP address (no code change in v4)
Without
Echo#IPExtractor,Context.RealIP()in v4 trusts theX-Forwarded-ForandX-Real-IPheaders from any client, so the rate limiter can be bypassed and the Proxy middleware forwards a spoofedX-Real-IP(GHSA-246p-cpwv-v3jq, GHSA-99jh-6h7p-pp36). Changing this default in v4 would put all clients behind a proxy into one rate-limit bucket, so v4 keeps it. Set an extractor that matches your deployment:v5 uses the direct peer address by default since v5.1.0.
Behavior changes to check before upgrading
100.64.0.0/10) address, itsX-Forwarded-Protois now ignored:HTTPSRedirectredirects in a loop and the Secure middleware stops sending HSTS. This affects, for example, Cloudflare, CloudFront and Azure Front Door connecting to a public origin, the GCP external HTTP(S) load balancer including GKE Ingress (35.191.0.0/16,130.211.0.0/22), and networks that use100.64.0.0/10(such as Alibaba Cloud SLB or EKS custom networking). Trust the proxy's address ranges:echo.LegacySchemeExtractor()restores the old behavior but is not safe unless every request passes through a proxy that sets these headers. Serverless adapters or middleware that setRemoteAddrto the client's address also makeX-Forwarded-Protoignored (or, if they take it from a header, spoofable).X-Forwarded-Proto. A proxy on a trusted address that passes the client'sX-Forwarded-Protothrough (for example nginx withoutproxy_set_header X-Forwarded-Proto $scheme;) still lets the client choose the scheme. An invalidX-Forwarded-Protovalue now results inhttpinstead of falling back to the other scheme headers.httptest.NewRequestsetsRemoteAddrto192.0.2.1:1234, which is not trusted, so tests that setX-Forwarded-Protonow seehttp. Setreq.RemoteAddr = "10.0.0.1:1234"or usee.SchemeExtractor = echo.LegacySchemeExtractor()in such tests.X-Forwarded-Ssl,X-Forwarded-ProtocolandX-Url-Schemeare no longer forwarded to the upstream;X-Forwarded-Protocarries the scheme.GET(for example withX-HTTP-Method-Override: GETto send a long query in a POST body) is no longer done; such requests keep the POST method./assets//app.js) now return 404; in HTML5 mode the index is still served. The Static middleware no longer finds file names that the client sends with non-default escaping (for example%2C,%40or lowercase hex like%c3%a9) unlessStaticConfig.EnablePathUnescapingis set;Echo.Statichas behaved this way since v4.15.4. WithStaticConfig.EnablePathUnescapingorEcho#EnablePathUnescapingStaticFiles, encoded dots (%2e%2e) no longer traverse directories, but encoded slashes are still decoded, so do not combine these options with route-based access control.Context.JSONPreturns an error for callbacks that are not JavaScript identifiers.Documentation
Echo#Useit runs before route and group middleware, so route guards do not protect the files it serves.Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.