fix(deps): update module github.com/cli/go-gh/v2 to v2.11.1 [security] #77
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
v2.11.0
->v2.11.1
GitHub Vulnerability Alerts
CVE-2024-53859
Summary
A security vulnerability has been identified in
go-gh
that could leak authentication tokens intended for GitHub hosts to non-GitHub hosts when within a codespace.Details
go-gh
sources authentication tokens from different environment variables depending on the host involved:GITHUB_TOKEN
,GH_TOKEN
for GitHub.com and ghe.comGITHUB_ENTERPRISE_TOKEN
,GH_ENTERPRISE_TOKEN
for GitHub Enterprise ServerPrior to
2.11.1
,auth.TokenForHost
could source a token from theGITHUB_TOKEN
environment variable for a host other than GitHub.com or ghe.com when within a codespace.In
2.11.1
,auth.TokenForHost
will only source a token from theGITHUB_TOKEN
environment variable for GitHub.com or ghe.com hosts.Impact
Successful exploitation could send authentication token to an unintended host.
Remediation and mitigation
go-gh
to2.11.1
Release Notes
cli/go-gh (github.com/cli/go-gh/v2)
v2.11.1
Compare Source
Security
A security vulnerability has been identified in go-gh that could leak authentication tokens intended for GitHub hosts to non-GitHub hosts when within a codespace.
For more information, see GHSA-55v3-xh23-96gh
Full Changelog: cli/go-gh@v2.11.0...v2.11.1
Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.