
We are building k9s into a go-dev-container and trivy security scanning is detecting the above mentioned critical vulnerability in k9s. See screenshot below.
A few thoughts.
- You have a lot of PRs from dependabot waiting to be merged. Any reason why?
- Recommend turning on trivy scanning.
- Recommend running your repo through https://app.stepsecurity.io/securerepo This tool is recommended by the ossf scorecard. Another security tool you can look into if you like.
Also CVE-2024-6257 , see second screenshot below.

Also

We are building k9s into a go-dev-container and trivy security scanning is detecting the above mentioned critical vulnerability in k9s. See screenshot below.
A few thoughts.
Also CVE-2024-6257 , see second screenshot below.
Also