Releases: aquasecurity/tfsec
Releases · aquasecurity/tfsec
v1.28.14
What's Changed
- fix: CVE-2025-22869: Denial of Service in the Key Exchange of golang.org/x/crypto/ssh by @jdesouza in #2172
- chore: update and clean up golangci-lint by @mmorel-35 in #2165
- chore: update golangci lint by @simar7 in #2175
- chore(deps): bump golang.org/x/net from 0.33.0 to 0.38.0 by @dependabot in #2174
- chore(deps): bump golangci-lint to v2.1 by @mmorel-35 in #2176
New Contributors
- @mmorel-35 made their first contribution in #2165
Full Changelog: v1.28.13...v1.28.14
v1.28.13
v1.28.12
Changelog
- 7f016e7 CVE-2024-45337: Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass (#2162)
v1.28.11
What's Changed
- Upgrading deps by @jdesouza in #2157
- chore(deps): bump github.com/open-policy-agent/opa from 0.44.1-0.20220927105354-00e835a7cc15 to 0.68.0 by @dependabot in #2158
Full Changelog: v1.28.10...v1.28.11
v1.28.10
v1.28.9
v1.28.8
v1.28.7
What's Changed
- fix: typo by @testwill in #2110
- Bumped Go-Getter due High Vulnerability CVE-2024-6257 by @jdesouza in #2145
- chore(deps): bump golang.org/x/net from 0.19.0 to 0.23.0 by @dependabot in #2146
- chore(deps): bump google.golang.org/protobuf from 1.30.0 to 1.33.0 by @dependabot in #2147
New Contributors
Full Changelog: v1.28.6...v1.28.7
v1.28.6
v1.28.5
What's Changed
- Create auto-close-issues.yml by @simar7 in #2104
- chore(deps): bump github.com/go-git/go-git/v5 from 5.5.2 to 5.11.0 by @dependabot in #2131
- chore(deps): bump google.golang.org/grpc from 1.52.0 to 1.56.3 by @dependabot in #2132
- chore(deps): bump golang.org/x/crypto from 0.16.0 to 0.17.0 by @dependabot in #2133
- chore(deps): bump github.com/cloudflare/circl from 1.3.3 to 1.3.7 by @dependabot in #2134
Full Changelog: v1.28.4...v1.28.5