Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

replace whilp/git-urls module by chainguard-dev/git-urls #12

Merged
merged 1 commit into from
Dec 10, 2023

Conversation

hectorj2f
Copy link
Contributor

We discovered a vulnerability on the module github.com/whilp/git-urls GHSA-3f2q-6294-fmq5. This repository doesn't look to be maintained at this moment. That is why we decided to fix the vulnerability and move the repository over our organization. We plan to maintain this repository in the future.

Signed-off-by: Hector Fernandez <hector@chainguard.dev>
@matthyx
Copy link
Contributor

matthyx commented Dec 10, 2023

thanks @hectorj2f I've opened a similar PR to our main repo: kubescape/kubescape#1561
do you suggest completely replacing the package like you did, or replace it in go.mod like in mine?

@hectorj2f
Copy link
Contributor Author

@matthyx I would encourage you to avoid using replace here. We are changing the whole path on the source code. It is less confusing to keep the dep like this in the future.

@matthyx
Copy link
Contributor

matthyx commented Dec 10, 2023

Awesome I'll modify the other one tomorrow

@matthyx matthyx merged commit 36432da into kubescape:master Dec 10, 2023
3 checks passed
@hectorj2f
Copy link
Contributor Author

Thanks

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants