Skip to content

vendor: github.com/cyphar/filepath-securejoin v0.2.4#46923

Merged
thaJeztah merged 1 commit intomoby:masterfrom
thaJeztah:update_securejoin
Dec 11, 2023
Merged

vendor: github.com/cyphar/filepath-securejoin v0.2.4#46923
thaJeztah merged 1 commit intomoby:masterfrom
thaJeztah:update_securejoin

Conversation

@thaJeztah
Copy link
Copy Markdown
Member

update the dependency to v0.2.4 to prevent scanners from flagging the vulnerability (GHSA-6xv5-86q9-7xr8 / GO-2023-2048). Note that that vulnerability only affects Windows, and is currently only used in runc/libcontainer, so should not impact our use (as that code is Linux-only).

full diff: cyphar/filepath-securejoin@v0.2.3...v0.2.4

- What I did

- How I did it

- How to verify it

- Description for the changelog

- A picture of a cute animal (not mandatory but encouraged)

update the dependency to v0.2.4 to prevent scanners from flagging the
vulnerability (GHSA-6xv5-86q9-7xr8 / GO-2023-2048). Note that that vulnerability
only affects Windows, and is currently only used in runc/libcontainer, so should
not impact our use (as that code is Linux-only).

full diff: cyphar/filepath-securejoin@v0.2.3...v0.2.4

Signed-off-by: Sebastiaan van Stijn <[email protected]>
@thaJeztah
Copy link
Copy Markdown
Member Author

thx! Let me bring this one in

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants