-
Notifications
You must be signed in to change notification settings - Fork 113
Commit
Based on https://nvd.nist.gov/vuln/detail/CVE-2021-3121, there is a vulnerability in the Go module `gogo/protobuf`. This is an indirect dependency of `shipwright/build`. Even though there seems to be only one change from the CVE fix that ripples down into our code base, it should be addressed by making sure we use the fixed version. Due to the fact it is an indirect dependency of the Kubernetes packages, it does not sound practical to bump the Kubernetes module versions. Make sure that fixed version of `gogo/protobuf` is used.
- Loading branch information
There are no files selected for viewing
Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.
Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.
Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.
Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.
Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.
Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.