Fixes for CVE-2020-2616 and CVE-2022-24921 on actions-runner-controller image ! #1230
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Update Dockerfile, github/github.go, go.mod and go.sum for fixing CVE-2020-26160 and CVE-2022-24921 on actions-runner-controller image.
PR raised to fix Issue
Steps performed: (for fixing CVE-2022-24921)
Steps performed: (for fixing CVE-2020-26160)
github.com/dgrijalva/jwt-go repo is no longer maintained and is moved to new path https://github.com/dgrijalva/jwt-go#this-repository-is-no-longer-maintaned.
bradleyfalzon/ghinstallation
which was usingdgrijalva/jwt-go
also updated on its version2.0.3
to use the migrated repo. https://github.com/bradleyfalzon/ghinstallation/releases/tag/v2.0.3git.luolix.top/bradleyfalzon/ghinstallation/v2 v2.0.3
/bradleyfalzon/ghinstallation
go mod tidy