Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update github.com/go-jose/go-jose/v3 again #104

Closed
DrDaveD opened this issue Mar 11, 2024 · 5 comments
Closed

Update github.com/go-jose/go-jose/v3 again #104

DrDaveD opened this issue Mar 11, 2024 · 5 comments

Comments

@DrDaveD
Copy link

DrDaveD commented Mar 11, 2024

go-jose version 3.0.3 has a fix for another security vulnerability, please upgrade.

Is containers/ocicrypt not set up for dependabot?

stefanberger added a commit to stefanberger/ocicrypt that referenced this issue Mar 11, 2024
To avoid a potential DoS vulnerability in v3.0.0 update to v3.0.3.

Resolves: Issue containers#104
Signed-off-by: Stefan Berger <[email protected]>
@stefanberger
Copy link
Collaborator

Is containers/ocicrypt not set up for dependabot?

It is but I haven't heared from it. Strange. I just sent a PR.

stefanberger added a commit that referenced this issue Mar 11, 2024
To avoid a potential DoS vulnerability in v3.0.0 update to v3.0.3.

Resolves: Issue #104
Signed-off-by: Stefan Berger <[email protected]>
@stefanberger
Copy link
Collaborator

Should be fixed now.

@DrDaveD
Copy link
Author

DrDaveD commented Mar 11, 2024

Thanks. Can we please have a new release?

@stefanberger
Copy link
Collaborator

Thanks. Can we please have a new release?

I will make one soon.

@stefanberger
Copy link
Collaborator

Published v1.1.10 now.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants