Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update golang library dependencies to address possible vulnerabilities #34

Merged
merged 2 commits into from
May 5, 2024

Conversation

ShellyKa13
Copy link
Collaborator

*Bump golang.org/x/net v0.19.0 -> v0.23.0

Address CVE-2023-45288
https://nvd.nist.gov/vuln/detail/CVE-2023-45288

*Bump google.golang.org/protobuf v1.32.0 -> v1.33.0

This solves CVE-2024-24786

https://www.cve.org/CVERecord?id=CVE-2024-24786

@ShellyKa13 ShellyKa13 requested a review from arnongilboa May 5, 2024 14:48
@arnongilboa arnongilboa merged commit a7a6345 into kiagnose:main May 5, 2024
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants