Skip to content

Update github.com/cyphar/filepath-securejoin #23

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 1 commit into from
May 13, 2024

Conversation

andrewkroh
Copy link
Member

Update to github.com/cyphar/filepath-securejoin from v0.2.2 to v0.2.5.

Relates to https://pkg.go.dev/vuln/GO-2023-2048.

Example traces found:
#1: dependency/dependency.go:85:41: dependency.LoadOverrides calls filepath.SecureJoin

Update to github.com/cyphar/filepath-securejoin from v0.2.2 to v0.2.5.

Relates to https://pkg.go.dev/vuln/GO-2023-2048.

Example traces found:
    elastic#1: dependency/dependency.go:85:41: dependency.LoadOverrides calls filepath.SecureJoin
@andrewkroh
Copy link
Member Author

andrewkroh commented May 9, 2024

Hi @barkbay, as one of the more recent contributors to the repo could you help our with reviewing/merging this PR? I don't have permissions. Thanks.

side-note: We should get this repo listed in backstage so it's more clear what team owns this.

@barkbay barkbay merged commit 0bb3371 into elastic:master May 13, 2024
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants