Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade go-openapi/strfmt #132

Merged
merged 2 commits into from
Nov 22, 2022
Merged

Upgrade go-openapi/strfmt #132

merged 2 commits into from
Nov 22, 2022

Conversation

pierluc-codes
Copy link
Contributor

@pierluc-codes pierluc-codes commented Nov 18, 2022

🛠️ Description

Upgrade go-openapi/strfmt. mongo-driver v1.4.6 is vulnerable to CVE-2021-20329

🔗 External Links

CVE-2021-20329

@hashicorp-cla
Copy link

hashicorp-cla commented Nov 18, 2022

CLA assistant check
All committers have signed the CLA.

@bcmdarroch
Copy link
Contributor

Oops we really need to get dependabot set up on this repo 😅

@pierluc-codes
Copy link
Contributor Author

@bcmdarroch Yes! That is a good idea! Do you have an idea how we can automagically satisfy the changelog check? 🤔

@bcmdarroch
Copy link
Contributor

bcmdarroch commented Nov 21, 2022

The automated changelog is new, so unfortunately no auto-magic for dependency bumps yet. Just need a 132.txt with Bump github.com/go-openapi/strfmt from 0.20.0 to 0.21.3 (https://github.com/hashicorp/hcp-sdk-go/pull/132) in this format

@pierluc-codes pierluc-codes marked this pull request as ready for review November 21, 2022 22:00
@pierluc-codes pierluc-codes requested a review from a team November 21, 2022 22:00
@pierluc-codes pierluc-codes merged commit 134d5f2 into main Nov 22, 2022
@pierluc-codes pierluc-codes deleted the pierluc-codes/upgrade-strfmt branch November 22, 2022 14:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

3 participants