jackc / pgx

PostgreSQL driver and toolkit for Go
MIT License
10.84k stars 846 forks source link

Security: Uncaught Exception Violation found by Snyk #2092

Open leslie-corbalt opened 4 months ago

leslie-corbalt commented 4 months ago

I have the following required packages in go.mod: github.com/jackc/pgx/v5 v5.6.0 github.com/jmoiron/sqlx v1.3.5

My code imports: "github.com/jmoiron/sqlx" "_ github.com/jackc/pgx/v5/stdlib"

Snyk found a vulnerability, Uncaught Exception in pgx/v4, introduced through github.com/jackc/pgx@v5.6.0.

image

leslie-corbalt commented 4 months ago

It was introduced on July 2, 2024:

image

jackc commented 4 months ago

I have no idea what Snyk is doing. But every time a Snyk issue has been raised before it has been a false positive.

randecarlson commented 2 months ago

I notice that the OP imports .../V5/stdlib yet the snyk report references V4/stdlib...