Skip to content

Vulnerable dependencies #3569

@anna-agafonova

Description

@anna-agafonova

Describe the bug
Dependencies have been last updated two years ago.

There is a number of high risk known CVEs intorduced by golang.org/x/net@v0.17.0:

golang.org/x/net@v0.17.0 -> CWE-770, CVE-2023-45288, CVSS 8.7, CVSS v4.0 8.8, CVSS v3.1 8.2, CVSS v4.0 8.7, CVSS v3.1 7.5

Expected behavior

  • golang.org/x/net is updated to non-vulnerable version. Latest is 0.48.0
  • other dependencies are updated

Metadata

Metadata

Assignees

No one assigned

    Labels

    kind/bugBug related issuestaleStale - Bot reminder

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions