Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

ggcr: k8schain package depends on seemingly unmaintained ACR cred helper #1933

Open
hugoShaka opened this issue Apr 25, 2024 · 0 comments
Open
Labels
bug Something isn't working

Comments

@hugoShaka
Copy link

Describe the bug

The k8schain package depends on docker-credential-acr-env whose last release was 2 years ago and go module dependencies have not been updated since a year ago.

Some of its imported packages have known vulnerabilities, and even if the package itself does not rely on any vulnerable feature it still triggers some security scanners.

Additional context

Related to: #1042 (implementing it would not solve the fact the ACR cred helper is unmaintained, but it would avoid including it in the dependency tree by default)

@hugoShaka hugoShaka added the bug Something isn't working label Apr 25, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
None yet
Development

No branches or pull requests

1 participant