Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2023-39533 and other vulnerabilities in go 1.20.4. can you upgrade to go 1.20.7? #199

Closed
niole opened this issue Oct 10, 2023 · 5 comments · Fixed by #202
Closed

CVE-2023-39533 and other vulnerabilities in go 1.20.4. can you upgrade to go 1.20.7? #199

niole opened this issue Oct 10, 2023 · 5 comments · Fixed by #202

Comments

@niole
Copy link

niole commented Oct 10, 2023

Hi there, we use helm-push at the company where I work. This library depends on a go 1.20.4, which has known vulnerabilities. Is it possible to upgrade to go 1.20.7? I will take a look and see what it takes to upgrade.

@niole
Copy link
Author

niole commented Oct 11, 2023

@nerdeveloper wondering if you can take a look?

@niole
Copy link
Author

niole commented Oct 27, 2023

@czhujer @scbizu @nerdeveloper any thoughts on this? This would be huge for my company, which puts a big emphasis on security.

scbizu added a commit that referenced this issue Oct 28, 2023
scbizu added a commit that referenced this issue Oct 28, 2023
Fix #199, Closes #200

Signed-off-by: scbizu <scbizu@gmail.com>
@czhujer
Copy link
Contributor

czhujer commented Oct 29, 2023

yes, we should bump version fo golang :)

also bump helm package to 3.13 will good.

Maybe we should switch also yaml package check this: ghodss/yaml#81

@niole
Copy link
Author

niole commented Oct 30, 2023

@czhujer thanks so much!!!

@JohnniDi
Copy link

Yes, it would be greatly appreciated if all the open update PRs from dependaBot would make into a release soon.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

3 participants