You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The text was updated successfully, but these errors were encountered:
miselico
changed the title
Recheck whether security issue with git-urls has been resolved
Re-check whether security issue with git-urls has been resolved
Jan 21, 2024
* updating to go 1.21, also upgrading versions in blubber and upgrading dependencies
* explicitly specifying the toolchain breaks codeQL, so left that commented out
* Semgrep is no longer availble for unattended workflows as it used to be, that is now not part of the workflow any longer. Issue created for considering an alternative #82
* also temporarily replacing the vulnerable git-urls package with a version which has the vulnerability fixed see #83
---------
Co-authored-by: Michael Cochez <miselico@users.noreply.github.com>
We added
because the former has a security vulnerability. As long as this is not fixed, we use this alternative.
See whilp/git-urls#25 for a pull request which would solve this.
The text was updated successfully, but these errors were encountered: