Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bumps to fix cve-2024-24790 #4143

Merged
merged 2 commits into from
Jun 21, 2024
Merged

Bumps to fix cve-2024-24790 #4143

merged 2 commits into from
Jun 21, 2024

Conversation

geyslan
Copy link
Member

@geyslan geyslan commented Jun 21, 2024

1. Explain what the PR does

0841d44 fix(build): extract OPA 0.66 from OPA dev image
66b7b5e fix(build): bump go to fix cve-2024-24790

0841d44 fix(build): extract OPA 0.66 from OPA dev image

This workaround is required since OPA 0.65.0 (latest published release)
has cve-2024-24790.

After solved we can rollback to the previouw installation method.

2. Explain how to test it

3. Other comments

@geyslan geyslan requested a review from rscampos June 21, 2024 21:08
@geyslan geyslan self-assigned this Jun 21, 2024
This workaround is required since OPA 0.65.0 (latest published release)
has cve-2024-24790.

After solved we can rollback to the previouw installation method.
@geyslan geyslan merged commit ef7d74e into aquasecurity:main Jun 21, 2024
2 checks passed
@geyslan geyslan deleted the go-bump branch June 28, 2024 18:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant