This fixes a vulnerability in `go get` (CVE-2018-6574, http://golang.org/issue/23672), but shouldn't really affect our code, but it's good to keep in sync. Signed-off-by: Sebastiaan van Stijn <github@gone.nl> Upstream-commit: caeab268430a033fedd27c53be16758ac1a0f71e Component: engine