microsoft / azurelinux

Linux OS for Azure 1P services and edge appliances
MIT License
4.08k stars 497 forks source link

keda: patch CVE-2024-28180 in vendored gopkg.in/square/go-jose.v2 #9552

Open SeanDougherty opened 2 days ago

SeanDougherty commented 2 days ago
Merge Checklist

All boxes should be checked before merging the PR (just tick any boxes which don't apply to this PR)


Summary

This PR patches a vendored dependency, go-jose.v2, in the keda package to address CVE-2024-28180.

Change Log
Does this affect the toolchain?

NO

Associated issues
Links to CVEs
Test Methodology