This fixes a vulnerability in `go get` (CVE-2018-6574, http://golang.org/issue/23672), but shouldn't really affect our code, but it's good to keep in sync. Signed-off-by: Sebastiaan van Stijn <github@gone.nl> Upstream-commit: 6263b1254b179af81ff4ef97563fe2e1a053993a Component: packaging