Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

*: upgrade go crypto #454

Closed
wants to merge 1 commit into from
Closed

Conversation

cmars
Copy link

@cmars cmars commented Jan 19, 2022

This upgrades golang.org/x/crypto, mitigating the following security
vulnerabilities in this dependency:

https://app.snyk.io/vuln/SNYK-GOLANG-GOLANGORGXCRYPTO-1083910
https://app.snyk.io/vuln/SNYK-GOLANG-GOLANGORGXCRYPTOSSH-551923

This upgrades golang.org/x/crypto, mitigating the following security
vulnerabilities in this dependency:

https://app.snyk.io/vuln/SNYK-GOLANG-GOLANGORGXCRYPTO-1083910
https://app.snyk.io/vuln/SNYK-GOLANG-GOLANGORGXCRYPTOSSH-551923
@jlourenc
Copy link

Hey @mcuadros, it seems that #403 fixes the security vulnerabilities defined above as well as https://security.snyk.io/vuln/SNYK-GOLANG-GOLANGORGXCRYPTOSSH-2331920. However, the changes were not released, can you please release a v5.4.3 ?

Getting this PR in before releasing a new version would probably be a good move though.

@cmars cmars closed this Apr 25, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants