Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

x/vuln: Vulnerability with Go 1.22 but I'm using 1.21.8 #66301

Closed
o-lee opened this issue Mar 13, 2024 · 6 comments
Closed

x/vuln: Vulnerability with Go 1.22 but I'm using 1.21.8 #66301

o-lee opened this issue Mar 13, 2024 · 6 comments
Assignees
Labels
vulncheck or vulndb Issues for the x/vuln or x/vulndb repo WaitingForInfo Issue is not actionable because of missing required information, which needs to be provided.

Comments

@o-lee
Copy link

o-lee commented Mar 13, 2024

Currently after running a govulncheck on my project, it shows I'm affected by 2 vulnerabilities (GO-2024-2598 and GO-2024-2599) that affects go1.22. The issue is I'm using 1.21.8 which is not affected. Is there any way for govulncheck not to flag these as vulnerabilities?
Screenshot 2024-03-13 at 3 18 15 PM

@gopherbot gopherbot added the vulncheck or vulndb Issues for the x/vuln or x/vulndb repo label Mar 13, 2024
@gopherbot gopherbot modified the milestones: Unreleased, vuln/unplanned Mar 13, 2024
@seankhliao
Copy link
Member

seankhliao commented Mar 13, 2024

please fill out the bug report template.
and prefer to use text not images.

@seankhliao seankhliao added the WaitingForInfo Issue is not actionable because of missing required information, which needs to be provided. label Mar 13, 2024
@o-lee
Copy link
Author

o-lee commented Mar 14, 2024

please fill out the bug report template. and prefer to use text not images.

Do you mind pointing me to the bug template? When I click on Open for x/vulndb bugs or feature requests from here, it opens a new issue without a template.

@seankhliao
Copy link
Member

@seankhliao seankhliao added WaitingForInfo Issue is not actionable because of missing required information, which needs to be provided. and removed WaitingForInfo Issue is not actionable because of missing required information, which needs to be provided. labels Mar 15, 2024
@zpavlinovic
Copy link
Contributor

Is there a new issue for this? Reproduction steps would be really helpful here.

@zpavlinovic zpavlinovic self-assigned this Mar 26, 2024
@timothy-king
Copy link
Contributor

As an alternative to a reproducer steps, you can also provide the information about the packages we likely need to understand this. For similar go1.21 to go1.22 issues, what I needed was the contents of go env, go version -m vulncheck and the internal go list commands used by go/packages. FYI you can print the go list commands by running vulncheck with GOPACKAGESDEBUG=true and then running those commands it prints out manually from the same directory and piping this into a file.

This will reveal a lot about the package structure of your code. So if this is sensitive, you may want to share those as files outside of this issue.

@gopherbot
Copy link
Contributor

Timed out in state WaitingForInfo. Closing.

(I am just a bot, though. Please speak up if this is a mistake or you have the requested information.)

@gopherbot gopherbot closed this as not planned Won't fix, can't repro, duplicate, stale Apr 15, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
vulncheck or vulndb Issues for the x/vuln or x/vulndb repo WaitingForInfo Issue is not actionable because of missing required information, which needs to be provided.
Projects
None yet
Development

No branches or pull requests

5 participants