We use gosu in few of our Docker images and we also use Trivy security scanner before app deployment and since few days Trivy detects two critical vulnerabilities in gosu:
I doubt that gosu is heavily impacted by those issues, but it's anyway detected and just annoying.
Would it be possible to rebuild gosu and release new version with up to date deps?
Hey,
We use
gosu
in few of our Docker images and we also use Trivy security scanner before app deployment and since few days Trivy detects two critical vulnerabilities ingosu
:I doubt that
gosu
is heavily impacted by those issues, but it's anyway detected and just annoying. Would it be possible to rebuildgosu
and release new version with up to date deps?