Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Version bump in order to fix security issues in Go libraries #531

Closed

Conversation

rodrigodealer
Copy link

This PR fixes vulnerabilities issues both in golang.org/x/net and golang.org/x/text

Link for the vulnerabilities CVEs:

cve-2022-41717
cve-2022-32149
cve-2022-41723

The propose of this change is to correct vulnerabilities in both golang text and net packages. I've got this issue when I was running trivy against a source code and it flagged them as high risk vulnerabilities and thought would make sense to propose this change, since it wasn't already proposed.

@rodrigodealer
Copy link
Author

@bnfinet Could you have a look at this PR?

@vouch vouch deleted a comment from rvignesh89 Jul 9, 2023
@vouch vouch deleted a comment from halkeye Jul 9, 2023
@vouch vouch deleted a comment from rvignesh89 Jul 9, 2023
@yonas
Copy link

yonas commented Oct 20, 2024

This can be closed - versions have been bumped.

@rodrigodealer rodrigodealer deleted the version-bump-golang branch October 20, 2024 09:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants