Skip to content

Conversation

@ajayk
Copy link

@ajayk ajayk commented Jan 31, 2024

Moves from unmaintained go-git.v4 to go-git.v5 and as the go-git.v4 has a critical CVE https://pkg.go.dev/vuln/GO-2024-2466

and updates golang.org/x/net and x/crypto and circl to latest versions bunch of cve's reported in older versions

@ajayk ajayk changed the title moce from go-git.v4 to go-git.v5 move from go-git.v4 to go-git.v5 Jan 31, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant