Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore: update dependencies #347

Open
wants to merge 3 commits into
base: main
Choose a base branch
from

Conversation

reneleonhardt
Copy link

Fixes CVE-2023-39325

How is this repo being managed, is it scanned daily by trivy?
Dependabot offered the fix 3 weeks ago, can you release a new Docker build?

@reneleonhardt reneleonhardt requested a review from a team as a code owner November 1, 2023 10:34
@reneleonhardt reneleonhardt requested review from skpratt and removed request for a team November 1, 2023 10:34
@hashicorp-cla
Copy link

hashicorp-cla commented Nov 1, 2023

CLA assistant check
All committers have signed the CLA.

@marrws
Copy link

marrws commented Nov 13, 2023

Dependabot also reported this #344

@reneleonhardt
Copy link
Author

Thank you for merging Dependabot, can you release a new version and build Docker images so downstream users can update?

@skpratt skpratt requested review from a team and removed request for skpratt November 16, 2023 18:18
@reneleonhardt reneleonhardt changed the title chore: update dependencies to fix CVE-2023-39325 chore: update dependencies Nov 17, 2023
@reneleonhardt
Copy link
Author

Your build seems a bit strange, Dependabot sees go.mod 1.20 but your ci.yml uses 1.21... and then go test complains about needing go mod tidy, would be easier for everyone if you decide which version you want 😅
Your users still need a new tag and Docker build so they can fix the security bugs in v0.13.2 🙂

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants