Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Re-check whether security issue with git-urls has been resolved #83

Open
miselico opened this issue Jan 21, 2024 · 0 comments
Open

Re-check whether security issue with git-urls has been resolved #83

miselico opened this issue Jan 21, 2024 · 0 comments
Labels
dependency Issues related to dependencies

Comments

@miselico
Copy link
Collaborator

We added

replace github.com/whilp/git-urls v1.0.0 => github.com/chainguard-dev/git-urls v1.0.2

because the former has a security vulnerability. As long as this is not fixed, we use this alternative.

See whilp/git-urls#25 for a pull request which would solve this.

@miselico miselico changed the title Recheck whether security issue with git-urls has been resolved Re-check whether security issue with git-urls has been resolved Jan 21, 2024
miselico added a commit that referenced this issue Jan 21, 2024
* updating to go 1.21, also upgrading versions in blubber and upgrading dependencies
* explicitly specifying the toolchain breaks codeQL, so left that commented out
* Semgrep is no longer availble for unattended workflows as it used to be, that is now not part of the workflow any longer. Issue created for considering an alternative #82
* also temporarily replacing the vulnerable git-urls package with a version which has the vulnerability fixed see #83

---------

Co-authored-by: Michael Cochez <miselico@users.noreply.github.com>
@miselico miselico added the dependency Issues related to dependencies label Mar 2, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependency Issues related to dependencies
Projects
None yet
Development

No branches or pull requests

1 participant