go-gorm / postgres

GORM PostgreSQL driver
MIT License
225 stars 119 forks source link

CVE GO-2024-2606 - Need to bump `pgx` version #260

Closed LJ-Software closed 2 months ago

LJ-Software commented 5 months ago

CVE Link

https://github.com/jackc/pgx/security/advisories/GHSA-mrww-27vc-gghv and https://pkg.go.dev/vuln/GO-2024-2606

Description

There is a public CVE for github.com/jackc/pgx that can be remedied by updating pgx to v5.5.4.

Solution

Update dependency pgx to version > v5.5.4

91pavan commented 3 months ago

@jinzhu can you please release a new version for GORM?