Skip to content

Conversation

@Inigo4562
Copy link

@Inigo4562 Inigo4562 commented Oct 27, 2021

This upgrades to the latest stable versions and solves these two vulnerabilities:

  • github.com/gogo/protobuf | CVE-2021-3121 | HIGH | v1.3.1 (installed version) | v1.3.2 (fixed version)
  • golang.org/x/crypto | CVE-2020-29652 | HIGH | v0.0.0-20200220183623-bac4c82f6975 (installed version) | v0.0.0-20201216223049-8b5274cf687f (fixed version)
  • k8s.io/client-go | CVE-2020-8565 | MEDIUM | v0.18.2 (installed version) | v0.20.0-alpha.2 (installed version)

In order to make the go build stage work, golang needs to be updated as well to 1.16

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant