You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Our oso fork was flagged with unpatched vulnerable dependency remove_dir_all. Github advisory: GHSA-mc8h-8q98-g5hr
It seems Oso currently uses version 0.5.3, while the patched version is 0.8.0+.
It's not clear to me if the vulnerability is reachable/exploitable.
Please update the vulnerable library version or explain why the update is not needed (e.g. if this is not reachable/unexploitable in the way how Oso uses the dependency).
The text was updated successfully, but these errors were encountered:
It looks like that's pulled in as a transitive dependency of tempfile -- which is a package we use in development only for creating temporary files in tests, and of cbindingen -- which is a compile-time only dependency that generates C header files for us. Neither of these dependencies are included in any distributed components.
However, we'll still look to upgrade this dependency when possible.
Our oso fork was flagged with unpatched vulnerable dependency
remove_dir_all
. Github advisory: GHSA-mc8h-8q98-g5hrIt seems Oso currently uses version 0.5.3, while the patched version is 0.8.0+.
It's not clear to me if the vulnerability is reachable/exploitable.
Please update the vulnerable library version or explain why the update is not needed (e.g. if this is not reachable/unexploitable in the way how Oso uses the dependency).
The text was updated successfully, but these errors were encountered: