Skip to content

Security: Update @depot/cli to fix GHSA-v778-237x-gjrc (golang.org/x/crypto) #3009

@DarrenJCoxon

Description

@DarrenJCoxon

Summary

@depot/cli@0.0.1-cli.2.80.0 bundles golang.org/x/crypto@v0.19.0 which has a CRITICAL vulnerability (CVSS 9.1):

  • CVE: GHSA-v778-237x-gjrc
  • Issue: Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass
  • Fixed in: golang.org/x/crypto >= 0.31.0

Current State

  • @trigger.dev/sdk@4.3.3 depends on trigger.dev@4.3.3
  • trigger.dev@4.3.3 depends on @depot/cli@0.0.1-cli.2.80.0
  • @depot/cli@0.0.1-cli.2.101.3 is available on npm (likely contains the fix)

Impact

This vulnerability is flagged by Grype and other container/binary scanners, causing security audits to fail even though the actual exploitation risk may be low for most use cases.

Request

Please update @depot/cli to the latest version (0.0.1-cli.2.101.3 or newer).

Alternatively, consider making it an optional dependency per #1597, which would allow users who don't need Depot's container building features to avoid pulling in vulnerable binaries.

References

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions