-
Notifications
You must be signed in to change notification settings - Fork 177
Labels
dependenciesPull requests that update a dependency filePull requests that update a dependency filelow hanging 🍇Things that are relatively easy to solveThings that are relatively easy to solve
Milestone
Description
There are known vulnerabilities in the version of Go presently utilized in the latest version of Sensu Go 6.12.0
vulnerability_name source source name version fixed_version
CVE-2024-45338 GHSA-w32m-9786-jp63 LIBRARY golang.org/x/net 0.23.0 0.33.0
CVE-2024-0406 GHSA-rhh4-rh7c-7r5v LIBRARY github.com/mholt/archiver/v3 3.3.1-0.20191129193105-44285f7ed244
CVE-2024-51744 GHSA-29wx-vh33-7x7r LIBRARY github.com/golang-jwt/jwt/v4 4.5.0 4.5.1
Possible Solution
Please include the latest version of Go (and other dependencies) in the next release of Sensu Go
Metadata
Metadata
Assignees
Labels
dependenciesPull requests that update a dependency filePull requests that update a dependency filelow hanging 🍇Things that are relatively easy to solveThings that are relatively easy to solve