tianon / gosu

Simple Go-based setuid+setgid+setgroups+exec
Apache License 2.0
4.73k stars 321 forks source link

The v17 has many security vulnerables because of Go stdlib #150

Closed OlgasAcc closed 1 month ago

OlgasAcc commented 1 month ago

The version is vulnerable because of used Go stdlib v1.18.2:

image image image image image

Please upgrade the Go stdlib to v1.23 in gosu?

The use case: this is a release blocker for our project because of the postgres image which uses vulnerable gosu v17.

Thanks

tianon commented 1 month ago

https://github.com/tianon/gosu/blob/4233b796eeb3ba76c8597a46d89eab1f116188e2/SECURITY.md