-
Notifications
You must be signed in to change notification settings - Fork 116
Open
Labels
Description
Latest lifecycle release v0.20.7 triggered CVE(s) from Grype. For further details, see: https://github.com/buildpacks/lifecycle/actions/runs/14025896604 json: {
"id": "GHSA-mh63-6h87-95cp",
"severity": "High",
"description": "jwt-go allows excessive memory allocation during header parsing"
}