Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix: trim 0.0.1 has a CVE #720

Merged
merged 1 commit into from
Oct 28, 2022
Merged

fix: trim 0.0.1 has a CVE #720

merged 1 commit into from
Oct 28, 2022

Conversation

benoitf
Copy link
Collaborator

@benoitf benoitf commented Oct 28, 2022

What does this PR do?

Update 3rd party library to a fixed version
GHSA-w5p7-h5w8-2hfq

note that it's only used at build time so there is no way that it's impacting Podman Desktop at runtime
But it'll remove security alerts from scanners

Screenshot/screencast of this PR

What issues does this PR fix or reference?

GHSA-w5p7-h5w8-2hfq

How to test this PR?

It's used in docusaurus for markdown rendering

Change-Id: I74e3b64741eee14bc8d6d5105cc0f7d996b7d989
Signed-off-by: Florent Benoit fbenoit@redhat.com

GHSA-w5p7-h5w8-2hfq

note that it's only used at build time so there is no way
that it's impacting Podman Desktop at runtime
But it'll remove security alerts from scanners

Change-Id: I74e3b64741eee14bc8d6d5105cc0f7d996b7d989
Signed-off-by: Florent Benoit <fbenoit@redhat.com>
@cdrage cdrage merged commit 4883943 into containers:main Oct 28, 2022
@podman-desktop-bot podman-desktop-bot added this to the 0.10.0 milestone Oct 28, 2022
slemeur pushed a commit to deekay2310/podman-desktop that referenced this pull request Nov 2, 2022
GHSA-w5p7-h5w8-2hfq

note that it's only used at build time so there is no way
that it's impacting Podman Desktop at runtime
But it'll remove security alerts from scanners

Change-Id: I74e3b64741eee14bc8d6d5105cc0f7d996b7d989
Signed-off-by: Florent Benoit <fbenoit@redhat.com>

Signed-off-by: Florent Benoit <fbenoit@redhat.com>
Signed-off-by: Stévan Le Meur <1636769+slemeur@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

3 participants