getsolus / solbuild

The Solus package build system
https://getsol.us
Apache License 2.0
19 stars 12 forks source link

Security vulnerabilities in solbuild detected by Dependabot in golang mods #64

Closed TraceyC77 closed 6 months ago

TraceyC77 commented 8 months ago

getsolus / solbuild

Known security vulnerabilities detected Dependency golang.org/x/crypto Version < 0.17.0 Upgrade to ~> 0.17.0 Defined in go.mod Vulnerabilities CVE-2023-48795 Moderate severity

https://github.com/getsolus/solbuild/security/dependabot/7

TraceyC77 commented 8 months ago

There's an additional one now

Known security vulnerabilities detected Dependency golang.org/x/crypto Version < 0.17.0 Upgrade to ~> 0.17.0 Defined in go.mod Vulnerabilities CVE-2023-48795 Moderate severity Dependency github.com/cloudflare/circl Version < 1.3.7 Upgrade to ~> 1.3.7 Defined in go.mod Vulnerabilities GHSA-9763-4f94-gfch High severity

silkeh commented 6 months ago

Resolved in #73.