cockroachdb / errors

Go error library with error portability over the network
Apache License 2.0
2.07k stars 66 forks source link

CVE-2020-28483 by dependancies cockroachdb / sentry-go > gin-gonic / gin #69

Closed nabbar closed 3 years ago

nabbar commented 3 years ago

Hello,

Could you bump your dependancies to this repos and the sentry-go forked repos. The dependancies gin-gonic / gin at version < 1.7.0 is exposed to cve :

This dependancies are included into github.com/cockroachdb/sentry-go (cf go.mod at line 9). Could you please plan to publish new releqse of this repos and the forked sentry-go with a bump of dependancies ?

Thanks in advance.

knz commented 3 years ago

The crdb errors library is not exposed to these vulnerabilities, because it does not expose any gin-based HTTP service to the network.