jimmidyson / configmap-reload

Simple binary to trigger a reload when a Kubernetes ConfigMap is updated
Apache License 2.0
983 stars 193 forks source link

High CVE in go v1.20.5 #92

Closed MikeFindsThings closed 1 year ago

MikeFindsThings commented 1 year ago

CVE-2023-39533 exists in go v1.20.5 and resolved in v1.20.7. Could you please bump the version?

Alternatively, is configmap-reload even affected by this CVE?

cliffcolvin commented 1 year ago

I would greatly apprecaite seeing this updated as well. Many implementations are held by the security scan for this vulnerability.

jimmidyson commented 1 year ago

Sorry for the delay, should be fixed in #93.