Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

go.mod,sum: fix CVE-2020-8912 #603

Merged
merged 1 commit into from
May 3, 2021
Merged

go.mod,sum: fix CVE-2020-8912 #603

merged 1 commit into from
May 3, 2021

Conversation

eguzki
Copy link
Member

@eguzki eguzki commented Apr 30, 2021

This PR addresses CVE-2020-8912.

All the info about affected dependency and replaced version in https://issues.redhat.com/browse/THREESCALE-5928

After the replace directive is added, go.sum does not show affected version of the dep. On the other hand, go mod graph still shows affected versions of the dep, but according to this issue, code is being replaced.

@eguzki eguzki requested a review from miguelsorianod April 30, 2021 11:58
@eguzki eguzki merged commit 5af8541 into master May 3, 2021
@eguzki eguzki deleted the fix-CVE-2020-8912 branch May 3, 2021 10:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants