ejoffe / spr

Stacked Pull Requests on GitHub
MIT License
796 stars 68 forks source link

CVE-2022-29526 & CVE-2022-29526 #353

Closed yaneury closed 1 year ago

yaneury commented 1 year ago

Hello! 👋 ,

I'm a huge fan of this project and would like to use it at my company. Unfortunately, my company requires approval before using any open source tool. In this case, we can use once two vulnerabilities are fixed. Our internal scanning tool spotted CVE-2022-28948 and CVE-2022-29526 in this repo.

Can I draft a PR to address these? I think one should be fixed by bumping the Go version to 1.18, while the other needs a bit more investigation.

ejoffe commented 1 year ago

Yes, go for it. Pull Requests always welcome.