Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix: fix CVE-2024-45338 by forcing newer x/net #173

Merged
merged 1 commit into from
Dec 20, 2024

Conversation

kb-newrelic
Copy link
Contributor

@kb-newrelic kb-newrelic commented Dec 20, 2024

Summary

  • Similar fix to fix: fix CVE-2024-45337 with replace directive #165 as we can't wait for all dependency to be fixed
  • Added convenience target to run trivy against snapshot images generated by goreleaser. Intentionally didn't create a top-level delegation target as that should be done with caching of the trivy db across multiple distros which is a task for another day. The command can be executed from the distro directory.

@kb-newrelic kb-newrelic requested a review from a team as a code owner December 20, 2024 18:30
Copy link
Contributor

@mailo-nr mailo-nr left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@kb-newrelic kb-newrelic merged commit 2cbab54 into main Dec 20, 2024
6 checks passed
@kb-newrelic kb-newrelic deleted the kbauer/fix-CVE-2024-45338 branch December 20, 2024 18:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants