jackc / tern

The SQL Fan's Migrator
MIT License
850 stars 66 forks source link

Security vulnerability detected in current stable version #61

Closed mzanibelli closed 2 years ago

mzanibelli commented 2 years ago

Hello!

Our security scanners ring because of outdated golang.org/x/text/language in the binary. Would it be possible to bump golang.org/x/text to 0.3.7?

Thanks for this great tool and have a good day.

jackc commented 2 years ago

I bumped the dependency to the latest pgx which depends on the updated x/text module. Though FWIW, that vulnerable package isn't actually used by tern.

mzanibelli commented 2 years ago

Great, thank you so much for the quick answer.

Though FWIW, that vulnerable package isn't actually used by tern.

That's what I thought, detection bots were silenced for now 😄

Have a good day!