Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

go.mod: bump go-git to v5.13.0 #13255

Merged
merged 1 commit into from
Jan 6, 2025
Merged

go.mod: bump go-git to v5.13.0 #13255

merged 1 commit into from
Jan 6, 2025

Conversation

lbajolet-hashicorp
Copy link
Contributor

Version 5.11.0 of the go-git library is vulnerable to two CVEs as reported by our scanners.

Both are not impacting Packer since we only use go-git to read values from a local Git repository, but still we upgrade our version to 5.13.0 so those reports don't apply to us.

@lbajolet-hashicorp lbajolet-hashicorp added tech-debt Issues and pull requests related to addressing technical debt or improving the codebase dependencies Auto-pinning security Auto-pinning labels Jan 6, 2025
@lbajolet-hashicorp lbajolet-hashicorp requested a review from a team as a code owner January 6, 2025 20:34
Version 5.11.0 of the go-git library is vulnerable to two CVEs as
reported by our scanners.

Both are not impacting Packer since we only use go-git to read values
from a local Git repository, but still we upgrade our version to 5.13.0
so those reports don't apply to us.
@lbajolet-hashicorp lbajolet-hashicorp merged commit f24c978 into main Jan 6, 2025
11 checks passed
@lbajolet-hashicorp lbajolet-hashicorp deleted the bump_go-git branch January 6, 2025 20:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Auto-pinning security Auto-pinning tech-debt Issues and pull requests related to addressing technical debt or improving the codebase
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants