Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Please provide new release with newest go version #269

Closed
GeorgeAdye-Ki opened this issue Dec 19, 2024 · 3 comments
Closed

Please provide new release with newest go version #269

GeorgeAdye-Ki opened this issue Dec 19, 2024 · 3 comments

Comments

@GeorgeAdye-Ki
Copy link

GeorgeAdye-Ki commented Dec 19, 2024

We've been COPYing berglas into our containers with no issues until just now - our container scanning service which searches for CVE's has found the following problem:

HIGH severity vulnerability CVE-2024-45338 found affecting golang.org/x/net 0.29.0 and fixed in 0.33.0

Googling this CVE: https://advisories.gitlab.com/pkg/golang/golang.org/x/net/CVE-2024-45338/ details the vulnerability.

Is it possible for you to bump your dependency to golang.org/x/net v0.33.0 and create a new release?

@GeorgeAdye-Ki
Copy link
Author

Hi guys, just chasing this

@sraka1
Copy link

sraka1 commented Jan 29, 2025

Same issue with GHSA-v778-237x-gjrc

@sethvargo can you publish a new release please? The fix was already merged in #268

@sethvargo
Copy link
Member

v2.0.7

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants