Skip to content

Conversation

@matthewrj
Copy link
Contributor

Check List

Why

There are several vulnerabilities with the current versions of golang.org/x/crypto and golang.org/x/net:

Since tfcmt runs in a highly privileged environment where infrastructure can be modified it is important to address any vulnerabilities.

Solution

Upgrade to the latest versions of crypto, net where these vulnerabilities are fixed. I also upgrade sys as it seems like a good idea to upgrade them all in one go.

@suzuki-shunsuke
Copy link
Owner

Thank you for your contribution!

@suzuki-shunsuke suzuki-shunsuke added this to the v4.14.5 milestone Apr 15, 2025
@suzuki-shunsuke suzuki-shunsuke merged commit ec3f919 into suzuki-shunsuke:main Apr 15, 2025
11 checks passed
@suzuki-shunsuke
Copy link
Owner

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants