Skip to content

Conversation

@artem-y
Copy link
Owner

@artem-y artem-y commented Jan 3, 2025

In this PR:

  • bumped version of go-git dependency to v5.13.1

This change addresses "indirect parsing" security vulnerability fix suggested by dependabot: bumping indirect golang.org/x/net dependency to v0.33.0. While this tool alone is unlikely to pose a threat to the user because of given vulnerability, it still might be a risk if, for example, the tool is installed on a server in a pipeline where other scripts or programs have access to its invocation. TLDR: it's better to be safe then sorry=)

@artem-y artem-y added the dependencies Pull requests that update a dependency file label Jan 3, 2025
@artem-y artem-y self-assigned this Jan 3, 2025
@artem-y artem-y merged commit ec39018 into main Jan 3, 2025
1 check passed
@artem-y artem-y deleted the chore/bump-go-git-version branch January 3, 2025 16:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants