ory / hydra

The most scalable and customizable OpenID Certified™ OpenID Connect and OAuth Provider on the market. Become an OpenID Connect and OAuth2 Provider over night. Broad support for related RFCs. Written in Go, cloud native, headless, API-first. Available as a service on Ory Network and for self-hosters.
https://www.ory.sh/?utm_source=github&utm_medium=banner&utm_campaign=hydra
Apache License 2.0
15.66k stars 1.5k forks source link

Update version go-sqlite3 to 1.14.18 to fix vulnerability #3818

Closed mariovw-deriv closed 2 months ago

mariovw-deriv commented 3 months ago

To fix this critical vulnerability: https://nvd.nist.gov/vuln/detail/CVE-2023-7104

Related issue(s)

Checklist

Further Comments

CLAassistant commented 3 months ago

CLA assistant check
Thank you for your submission! We really appreciate it. Like many open source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution.
You have signed the CLA already but the status is still pending? Let us recheck it.

alnr commented 2 months ago

Thanks! Master is now on v1.14.22