Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

deps: bump golang.org/x/crypto to 0.5.0 #91

Merged
merged 1 commit into from
Jan 18, 2023
Merged

Conversation

radeksimko
Copy link
Member

While hc-install is not affected by the reported vulnerabilities - since all relate to SSH server (we use the client part of the library), it is good practice to keep dependencies up to date + this can reduce some unnecessary noise in security scanners.

@radeksimko radeksimko added the dependencies Auto-pinning label Jan 18, 2023
@radeksimko radeksimko requested a review from kmoe January 18, 2023 08:08
Copy link
Member

@bflad bflad left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good to me 🚀

@radeksimko radeksimko merged commit b979d40 into main Jan 18, 2023
@radeksimko radeksimko deleted the deps-bump-crypto-lib branch January 18, 2023 14:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Auto-pinning
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants