a8m / envsubst

Environment variables substitution for Go
MIT License
768 stars 83 forks source link

Request for New Release Built with Go 1.20.5+ to Address Security Vulnerabilities #62

Open jnielsen-monster opened 5 months ago

jnielsen-monster commented 5 months ago

Hello, The latest version of this great tool was built using a version of Go that contains some vulnerabilities, which now prevent us from using the tool. Could you please create a new version of this tool using a newer version of Go (1.20.5+ or 1.19.10+)?

List of critical vulnerabilities: https://nvd.nist.gov/vuln/detail/CVE-2023-24538 https://nvd.nist.gov/vuln/detail/CVE-2023-24540 https://nvd.nist.gov/vuln/detail/CVE-2023-29402 https://nvd.nist.gov/vuln/detail/CVE-2023-29404 https://nvd.nist.gov/vuln/detail/CVE-2023-29405