crossplane-contrib / function-patch-and-transform

A patch & transform composition function
https://crossplane.io
Apache License 2.0
23 stars 24 forks source link

CVE HIGH for golang.org/x/net, google.golang.org/protobuf #136

Closed haarchri closed 1 month ago

haarchri commented 1 month ago

we need to update our functions regarding the following CVEs:

[
{
"vuln": "CVE-2023-45288",
"url": "https://us2.app.sysdig.com/secure/#/vulnerabilities/results/17e4d1094a1a7f298be603fcc8ec3850/vulnerabilities/CVE-2023-45288",
"disclosure_date": "0001-01-01T00:00:00Z",
"severity": "High",
"fix": "v0.23.0",
"package_name": "golang.org/x/net",
"package_version": "v0.17.0",
"package_type": "golang",
"package_path": "/function",
"stop": true,
"exception": false,
"grace_period": false
},
{
"vuln": "CVE-2024-24786",
"url": "https://us2.app.sysdig.com/secure/#/vulnerabilities/results/17e4d1094a1a7f298be603fcc8ec3850/vulnerabilities/CVE-2024-24786",
"disclosure_date": "0001-01-01T00:00:00Z",
"severity": "High",
"fix": "v1.33.0",
"package_name": "google.golang.org/protobuf",
"package_version": "v1.31.0",
"package_type": "golang",
"package_path": "/function",
"stop": true,
"exception": false,
"grace_period": false
},
{
"vuln": "CVE-2023-48795",
"url": "https://us2.app.sysdig.com/secure/#/vulnerabilities/results/17e4d1094a1a7f298be603fcc8ec3850/vulnerabilities/CVE-2023-48795",
"disclosure_date": "0001-01-01T00:00:00Z",
"severity": "Medium",
"fix": "v0.17.0",
"package_name": "golang.org/x/crypto",
"package_version": "v0.14.0",
"package_type": "golang",
"package_path": "/function",
"stop": true,
"exception": false,
"grace_period": false
}
]