Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

cloudevents/sdk-go is vulnerable #247

Closed
jjustin opened this issue Jun 27, 2024 · 0 comments · Fixed by #248 or #245
Closed

cloudevents/sdk-go is vulnerable #247

jjustin opened this issue Jun 27, 2024 · 0 comments · Fixed by #248 or #245

Comments

@jjustin
Copy link

jjustin commented Jun 27, 2024

Hello!
https://github.com/cloudevents/sdk-go, a dependency of this project, is vulnerable. More details on the vulnerability: https://ossindex.sonatype.org/vulnerability/CVE-2024-28110. The vulnerability was fixed in v2.15.2.

I see there is already a dependabot PR open (#233). Would it be possible to look into that and prepare a release with the updated dependency?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
1 participant