Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Numerous critical/high security vulnerabilities found in Prisma scan #410

Closed
jeffshuberg opened this issue Nov 4, 2024 · 1 comment
Closed

Comments

@jeffshuberg
Copy link

The following critical/high security vulnerabilities have been found when performing a Prisma scan associated with using GO 1.17:

CVE-2022-23806, CVE-2022-28327, CVE-2022-41715, CVE-2022-30632, CVE-2023-45284, CVE-2023-24534, CVE-2023-24536, CVE-2023-24536, CVE-2022-41725, CVE-2022-32189, CVE-2022-23772, CVE-2022-30630, CVE-2022-24675, CVE-2022-30631, CVE-2023-39325, CVE-2022-41723, CVE-2022-27664, CVE-2021-44716, CVE-2022-21698, CVE-2023-45287, CVE-2022-41724, CVE-2023-29403, CVE-2022-24921

Please update to use GO 1.22+ and publish a new image to address these security vulnerabilities

Copy link

github-actions bot commented Nov 4, 2024

Thank you for submitting this issue!

We, the Members of Meteor Community Packages take every issue seriously.
Our goal is to provide long-term lifecycles for packages and keep up
with the newest changes in Meteor and the overall NodeJs/JavaScript ecosystem.

However, we contribute to these packages mostly in our free time.
Therefore, we can't guarantee you issues to be solved within certain time.

If you think this issue is trivial to solve, don't hesitate to submit
a pull request, too! We will accompany you in the process with reviews and hints
on how to get development set up.

Please also consider sponsoring the maintainers of the package.
If you don't know who is currently maintaining this package, just leave a comment
and we'll let you know

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant