-
v3.6.5 has CVE-2025-29786 for github.com/expr-lang/expr:1.16.9 What is the process for security vulnerabilities resolution on Argo-workflow |
Beta Was this translation helpful? Give feedback.
Answered by
tczhao
Apr 1, 2025
Replies: 1 comment 3 replies
-
If it's a direct dependency, we will have dependentbot raise the PR and auto merge #14307 |
Beta Was this translation helpful? Give feedback.
3 replies
Answer selected by
pkmmann
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
If it's a direct dependency, we will have dependentbot raise the PR and auto merge #14307
Looks like something failed, will fix it
for indirect dependency, we will have to wait for the parent package made the fix first.
Security fixes will get included in the next release