Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Build yq with 1.19.2 to remove various CVEs #1394

Closed
reece-oliver opened this issue Oct 21, 2022 · 2 comments
Closed

Build yq with 1.19.2 to remove various CVEs #1394

reece-oliver opened this issue Oct 21, 2022 · 2 comments
Labels

Comments

@reece-oliver
Copy link

Describe the bug

Build with go 1.19.2 to remove various CVEs, currently have various CVEs present which is stopping us ship our product

CVE               Severity   PackageName                        PackagePath                     Version              Status

CVE-2022-2880     high       go                                 /usr/local/bin/yq               1.19.1               fixed in 1.19.2, 1.18.7
CVE-2022-2879     high       go                                 /usr/local/bin/yq               1.19.1               fixed in 1.19.2, 1.18.7
CVE-2022-41715    high       go                                 /usr/local/bin/yq               1.19.1               fixed in 1.19.2, 1.18.7

Version of yq: 4.28.2

@reece-oliver
Copy link
Author

reece-oliver commented Oct 28, 2022

Is there any plan to make a new release soon? @mikefarah

@mikefarah
Copy link
Owner

yep - fixed in 4.29.1 :)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

2 participants