tianon / gosu

Simple Go-based setuid+setgid+setgroups+exec
Apache License 2.0
4.68k stars 312 forks source link

New CVEs Pertaining to Go Version #112

Closed jtk94 closed 2 years ago

jtk94 commented 2 years ago

Vulnerability scans using Twistlock are showing the following CVEs, all pertaining to go-1.17.7:

CVE-2022-1705 CVE-2022-1962 CVE-2022-28131 CVE-2022-30580 CVE-2022-30629 CVE-2022-30630 CVE-2022-30631 CVE-2022-30632 CVE-2022-30633

None of these findings are currently listed in #104. Can you confirm that these CVEs do not apply to builds of gosu?

tianon commented 2 years ago

Thanks, added!