aptible / supercronic

Cron for containers
MIT License
1.86k stars 113 forks source link

CVE-2023-24535 #132

Closed zwartho closed 1 year ago

zwartho commented 1 year ago

CVE-2023-24535 states that a vulnerability has been found in google.golang.org/protobuf@v1.26.0, which is an indirect dependency of supercronic. This vulnerability is remediated in google.golang.org/protobuf@v1.29.1. I recommend upgrading the direct dependency github.com/prometheus/client_golang@v1.12.2 to a version that includes this upgraded library (i.e. >= v1.15.0).