Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

update go-git to v5.12.0 to fix GO-2024-2456 #93

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

elchenberg
Copy link

@elchenberg elchenberg commented Sep 10, 2024

Summary

Update go-git to v5.12.0 to fix the critical severity vulnerability GO-2024-2456.

Disclaimer: I only “tested” the changes with make build.

Relates to #92.

Checklist

  • Keep pull requests small so they can be easily reviewed.
  • Categorize the PR by setting a good title and adding one of the labels:
    bug, enhancement, documentation, change, breaking,
    as they show up in the changelog
  • Link this PR to related issues.

@mhutter mhutter linked an issue Dec 2, 2024 that may be closed by this pull request
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Development

Successfully merging this pull request may close these issues.

govulncheck finds several dependencies with known vulnerabilities
2 participants