Skip to content

Dependency Security Assessment Failure #423

@garywarner

Description

@garywarner

Summary

The Sentry go module is dependent upon a number of third-party modules that have recognised security vulnerabilities.

Motivation

The security policy and vulnerability disclosure document (https://sentry.io/security/#vulnerability-disclosure) indicates that Sentry wishes to maintain a secure environment. Updating these modules will help maintain those aspiration.

Additional Context

There was a recent merge (#411) that resolved one of the other security vulnerabilities which I haven't listed, thank you. I hope that providing you this information will allow you to close these further two and perhaps do a security release.

These vulnerabilities were identified using Meterian where we are using github.com/getsentry/sentry-go:v0.12.0 in all our packages. The kataras module has three vulnerabilities caused by their third-party modules (github.com/microcosm-cc/bluemonday:v1.0.2, github.com/kataras/neffos:v0.0.14 and github.com/nats-io/nats.go:v1.9.1). The yaml vulnerability is self-contained.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions