You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
If I am not mistaken, wasn't CVE-2020-14040 fixed in golang.org/x/text v0.3.3, and the merging of PR #254 in commit 7686d4f updated afero's dependency on golang.org/x/text to v0.3.3 back in August 2020, and was released as afero v1.3.4, and that dependency remains to this day in afero v1.6.0?
That said, there are other fixes that are worth bumping dependency on golang.org/x/text to the newer v0.3.7
golang.org/x/text which has a here vulnerability as reported here:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14040
Short-term and Long-term upgrade fix is available in v0.3.7 for golang.org/x/text
Also impacts:
viper
The text was updated successfully, but these errors were encountered: