Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upstream pull #438

Closed
wants to merge 25 commits into from
Closed

Conversation

tanujbhatia1708
Copy link

No description provided.

ooms97 and others added 25 commits November 8, 2021 16:02
- Building and pushing images to our artifactory
Fixing latest tag not having the JFrog artifactory URL
* update grpcurl

* update grpcurl

* update grpcurl

* update grpcurl

* update grpcurl

* update grpcurl

* updated latest image for golang
* updated golang image

* updated golang version

* updated golang version

* updated golang version

* updated golang version

* updated golang version

* updated golang version

require (
github.com/golang/protobuf v1.5.2
github.com/jhump/protoreflect v1.13.0

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Dependency Risk: google.golang.org/[email protected] has 2 vulnerabilities

Upgrade to version 1.56.3 to mitigate all risks. This is a minor change from the installed version.

Severity: High 🚨
Status: Open 🔴

Vulnerabilities:

  1. GHSA-m425-mq94-257g - Severity: high - Fix: 1.56.3, 1.57.1, 1.58.3
  2. CVE-2023-44487 - Severity: medium - Fix: 1.58.3, 1.57.1, 1.56.3

You received this notification because a new code risk has been identified

github.com/envoyproxy/go-control-plane v0.10.2-0.20220325020618-49ff273808a1 // indirect
github.com/envoyproxy/protoc-gen-validate v0.1.0 // indirect
github.com/golang/protobuf v1.5.2 // indirect
golang.org/x/net v0.10.0 // indirect

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Dependency Risk: golang.org/x/[email protected] has 3 vulnerabilities

Upgrade to version 0.17.0 to mitigate all risks. This is a minor change from the installed version.

Severity: Medium ⚠️
Status: Open 🔴

Vulnerabilities:

  1. CVE-2023-39325 - Severity: medium - Fix: 0.17.0
  2. CVE-2023-3978 - Severity: medium - Fix: 0.13.0
  3. CVE-2023-44487 - Severity: medium - Fix: 0.17.0

You received this notification because a new code risk has been identified

@tanujbhatia1708
Copy link
Author

not needed

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants