You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Looking through the changelog and code artefacts for github.com/jackc/pgconn I can't see any reference to this feature being back-ported, or similar code which introduced the vulnerability. This would require follow-up from the developer for clarity but I'm fairly certain only v5 is affected.
Kind regards,
Chris
The text was updated successfully, but these errors were encountered:
Report ID
GO-2024-2567
Suggestion/Comment
Hello,
This got flagged in our CI and I'm not sure that github.com/jackc/pgx and github.com/jackc/pgx/v4 are affected.
My reasoning is that these packages import https://github.com/jackc/pgconn, whereas the v5.0.0 changelog states that
github.com/jackc/pgconn
got merged into the main repository. The vulnerable code was only introduced in v5.0.0-alpha.5 in this commit when adding a pipeline mode: jackc/pgx@ae2881aLooking through the changelog and code artefacts for
github.com/jackc/pgconn
I can't see any reference to this feature being back-ported, or similar code which introduced the vulnerability. This would require follow-up from the developer for clarity but I'm fairly certain only v5 is affected.Kind regards,
Chris
The text was updated successfully, but these errors were encountered: