Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

sec: update go-getter to latest version #2023

Merged
merged 2 commits into from
Apr 20, 2024

Conversation

Starttoaster
Copy link
Contributor

@Starttoaster Starttoaster commented Apr 20, 2024

Description

Related issues

go-getter is vulnerable to argument injection. This update closes that.

Checklist

  • I've read the guidelines for contributing to this repository.
  • I've added tests that prove my fix is effective or that my feature works.
  • I've updated the documentation with the relevant information (if needed).
  • I've added usage information (if the PR introduces new options)
  • I've included a "before" and "after" example to the description (if the PR is a user interface change).

@CLAassistant
Copy link

CLAassistant commented Apr 20, 2024

CLA assistant check
All committers have signed the CLA.

@Starttoaster Starttoaster changed the title Update go-getter to latest version chore: Update go-getter to latest version Apr 20, 2024
@github-actions github-actions bot added the misc label Apr 20, 2024
@chen-keinan
Copy link
Collaborator

chen-keinan commented Apr 20, 2024

@Starttoaster its in-direct dependency , it needed to be override otherwise its not fixed

Starttoaster and others added 2 commits April 20, 2024 14:51
@chen-keinan chen-keinan changed the title chore: Update go-getter to latest version sec: update go-getter to latest version Apr 20, 2024
@chen-keinan chen-keinan merged commit a509895 into aquasecurity:main Apr 20, 2024
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging this pull request may close these issues.

go-getter is vulnerable to argument injection
3 participants