hashicorp / go-getter

Package for downloading things from a string URL using a variety of protocols.
Mozilla Public License 2.0
1.62k stars 227 forks source link

Multiple Dependency Security Issues #477

Open zliang-akamai opened 3 months ago

zliang-akamai commented 3 months ago

There are many outdated vulnerable dependencies in this package and its sub-package, which are triggering downstream alerts. It would be very nice if we can get it fixed here rather overriding each of them while solving conflicts downstream.