Closed
Description
My company uses AWS Inspector to scan the container images we use in our CI environment and we are seeing a number of vulnerabilities in the latest version (0.10.3) of the Code Climate test reporter:
- https://snyk.io/vuln/SNYK-GOLANG-GOLANGORGXCRYPTO-2825234
- https://people.canonical.com/~ubuntu-security/cve/2020/CVE-2020-9283.html
- https://people.canonical.com/~ubuntu-security/cve/2020/CVE-2020-29652.html
All three are for the Go Crypto library: https://pkg.go.dev/golang.org/x/crypto
Metadata
Assignees
Labels
No labels