Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Go Cryptography vulnerabilities detected by AWS Inspector #496

Closed
davexunit opened this issue Jul 11, 2022 · 5 comments · Fixed by #497
Closed

Go Cryptography vulnerabilities detected by AWS Inspector #496

davexunit opened this issue Jul 11, 2022 · 5 comments · Fixed by #497
Assignees

Comments

@davexunit
Copy link

My company uses AWS Inspector to scan the container images we use in our CI environment and we are seeing a number of vulnerabilities in the latest version (0.10.3) of the Code Climate test reporter:

All three are for the Go Crypto library: https://pkg.go.dev/golang.org/x/crypto

@davexunit
Copy link
Author

I can see that the issue was fixed with the merging of #497 but what is the timeline for this fix making into, say, the binary download available via https://codeclimate.com/downloads/test-reporter/test-reporter-latest-linux-amd64 ?

@camillof
Copy link
Contributor

camillof commented Aug 9, 2022

It should be available once #500 goes in. I would say today/tomorrow.

@davexunit
Copy link
Author

Okay, thank you!

@camillof
Copy link
Contributor

Hey @davexunit , version 0.10.4 is out! Sorry for the delay, we had some incidents last week that took our full capacity

@gugacavalieri

This comment was marked as duplicate.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

5 participants