-
-
Notifications
You must be signed in to change notification settings - Fork 250
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
MegaLinter still uses vulnerable git version in docker images #2286
Comments
Fixed by #2312 :) |
@nvuillam I just pulled v6 images from Docker Hub, they still uses vulnerable version.
|
You'll see the update in beta version, and in the next v6.x release https://pkgs.alpinelinux.org/packages?name=git&branch=v3.17&repo=&arch=&maintainer= 2.38.3 is the latest version on alpine 3.17 |
Thanks, I misunderstood which version fixed the issue. 2.38.3 also fixes RCE vulnerabilities. |
All good so :) Thanks for reporting :) |
1 similar comment
All good so :) Thanks for reporting :) |
MegaLinter should update git client to 2.39.1 to fix CVE-2022-41903
The text was updated successfully, but these errors were encountered: