Looks like there's an open PR, #389 to address [GO-2025-3485](https://pkg.go.dev/vuln/GO-2025-3485). Is there anyway we can get that PR merged to address the security issue?