-
Notifications
You must be signed in to change notification settings - Fork 1.4k
fix(deps): vuln minor: github.com/aws/aws-sdk-go-v2/service/s3, github.com/go-git/go-git/v5 [test/e2e-framework] #50532
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Changes from all commits
479798a
40eae83
a79055b
ab87b79
a9ad27e
6ae4d17
30e9164
0a164aa
0a99433
bef3f5e
1a39585
6dd9b83
19b1098
d1974e7
00feafa
61d6443
de58070
1c6ca3a
b77236d
d65d6e2
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -134,8 +134,8 @@ require ( | |
| github.com/fxamacker/cbor/v2 v2.9.1 // indirect | ||
| github.com/go-errors/errors v1.5.1 // indirect | ||
| github.com/go-git/gcfg v1.5.1-0.20230307220236-3a3c6141e376 // indirect | ||
| github.com/go-git/go-billy/v5 v5.6.2 // indirect | ||
| github.com/go-git/go-git/v5 v5.16.5 // indirect | ||
| github.com/go-git/go-billy/v5 v5.9.0 // indirect | ||
| github.com/go-git/go-git/v5 v5.19.0 // indirect | ||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
This security remediation pins Useful? React with 👍 / 👎. There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
This security remediation now pins Useful? React with 👍 / 👎. There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
This security update leaves Useful? React with 👍 / 👎. There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
This security bump stops at Useful? React with 👍 / 👎. There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
This dependency update lands on Useful? React with 👍 / 👎. There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
This security update pins Useful? React with 👍 / 👎. There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
This security bump stops at Useful? React with 👍 / 👎. There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
This remediation still pins Useful? React with 👍 / 👎. There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
This dependency bump still pins Useful? React with 👍 / 👎. There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
Because the Useful? React with 👍 / 👎. There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
This security remediation still pins Useful? React with 👍 / 👎. There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
For this security-remediation update, pinning Useful? React with 👍 / 👎. There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. This security update lands on Useful? React with 👍 / 👎. There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
For this vulnerability-remediation update, Useful? React with 👍 / 👎. There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
This security remediation pins Useful? React with 👍 / 👎. There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
This pins Useful? React with 👍 / 👎. There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
This security update still pins Useful? React with 👍 / 👎. There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
This dependency bump still pins Useful? React with 👍 / 👎. There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
This security bump stops at Useful? React with 👍 / 👎. There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
This security update still pins Useful? React with 👍 / 👎. There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. This security-remediation update pins Useful? React with 👍 / 👎. There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
This security-remediation update pins Useful? React with 👍 / 👎. There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
This security remediation pins Useful? React with 👍 / 👎. There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
This security update pins Useful? React with 👍 / 👎. There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
This security-remediation PR still pins Useful? React with 👍 / 👎. There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
This security-remediation change pins Useful? React with 👍 / 👎. There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
This security update pins Useful? React with 👍 / 👎. There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
This remediation pins Useful? React with 👍 / 👎. There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
This security bump pins Useful? React with 👍 / 👎. There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
For this vulnerability-remediation update, pinning Useful? React with 👍 / 👎. There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
This security-remediation bump selects Useful? React with 👍 / 👎. There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
This remediation pins Useful? React with 👍 / 👎. |
||
| github.com/go-logr/logr v1.4.3 // indirect | ||
| github.com/go-logr/stdr v1.2.2 // indirect | ||
| github.com/go-openapi/jsonpointer v0.23.1 // indirect | ||
|
|
@@ -179,6 +179,7 @@ require ( | |
| github.com/json-iterator/go v1.1.12 // indirect | ||
| github.com/kevinburke/ssh_config v1.2.0 // indirect | ||
| github.com/klauspost/compress v1.18.6 // indirect | ||
| github.com/klauspost/cpuid/v2 v2.3.0 // indirect | ||
| github.com/kr/fs v0.1.0 // indirect | ||
| github.com/liggitt/tabwriter v0.0.0-20181228230101-89fcab3d43de // indirect | ||
| github.com/lucasb-eyer/go-colorful v1.4.0 // indirect | ||
|
|
@@ -209,7 +210,7 @@ require ( | |
| github.com/peterbourgon/diskv v2.0.1+incompatible // indirect | ||
| github.com/pgavlin/fx v0.1.6 // indirect | ||
| github.com/philhofer/fwd v1.2.0 // indirect | ||
| github.com/pjbgf/sha1cd v0.3.2 // indirect | ||
| github.com/pjbgf/sha1cd v0.6.0 // indirect | ||
| github.com/pkg/errors v0.9.1 // indirect | ||
| github.com/pkg/term v1.1.0 // indirect | ||
| github.com/planetscale/vtprotobuf v0.6.1-0.20240319094008-0393e58bdf10 // indirect | ||
|
|
||
Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This security remediation upgrades
github.com/go-git/go-git/v5only tov5.19.0, but the upstream advisory for GHSA-w5pp-99ch-qj29 marks<=5.19.0as affected and5.19.1as the patched version (GHSA-w5pp-99ch-qj29). In any E2E framework path that processes repository data via this transitive dependency, merging this still leaves a known moderate DoS vulnerability for malformed Git objects, so the remediation should target at leastv5.19.1.Useful? React with 👍 / 👎.