spf13 / viper

Go configuration with fangs
MIT License
26.77k stars 2.01k forks source link

update dependency github.com/hashicorp/consul/api v1.20.0 to latest version #1649

Closed GraHms closed 11 months ago

GraHms commented 11 months ago

Preflight Checklist

Viper Version

1.16.0

Go Version

1.20

Config Source

Environment variables

Format

No response

Repl.it link

No response

Code reproducing the issue

No response

Expected Behavior

No security violation

Actual Behavior

Nexus IQ reports this version as: Violation of Security-High

Policy Constraint High risk CVSS score is in violation for the following reason(s): Found security vulnerability CVE-2022-29153 with severity >= 7 (severity = 7.5) Found security vulnerability CVE-2022-29153 with severity < 9 (severity = 7.5)

Steps To Reproduce

No response

Additional Information

No response

github-actions[bot] commented 11 months ago

👋 Thanks for reporting!

A maintainer will take a look at your issue shortly. 👀

In the meantime: We are working on Viper v2 and we would love to hear your thoughts about what you like or don't like about Viper, so we can improve or fix those issues.

⏰ If you have a couple minutes, please take some time and share your thoughts: https://forms.gle/R6faU74qPRPAzchZ9

📣 If you've already given us your feedback, you can still help by spreading the news, either by sharing the above link or telling people about this on Twitter:

https://twitter.com/sagikazarmark/status/1306904078967074816

Thank you! ❤️