-
Notifications
You must be signed in to change notification settings - Fork 171
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
CVE-2023-39533 and other vulnerabilities in go 1.20.4. can you upgrade to go 1.20.7? #199
Comments
@nerdeveloper wondering if you can take a look? |
@czhujer @scbizu @nerdeveloper any thoughts on this? This would be huge for my company, which puts a big emphasis on security. |
yes, we should bump version fo golang :) also bump helm package to 3.13 will good. Maybe we should switch also yaml package check this: ghodss/yaml#81 |
@czhujer thanks so much!!! |
Yes, it would be greatly appreciated if all the open update PRs from dependaBot would make into a release soon. |
Hi there, we use helm-push at the company where I work. This library depends on a go 1.20.4, which has known vulnerabilities. Is it possible to upgrade to go 1.20.7? I will take a look and see what it takes to upgrade.
The text was updated successfully, but these errors were encountered: