Skip to content

go.mod: bump go-jose to 4.0.5#284

Merged
lbajolet-hashicorp merged 1 commit intomainfrom
bump_go_jose
Mar 28, 2025
Merged

go.mod: bump go-jose to 4.0.5#284
lbajolet-hashicorp merged 1 commit intomainfrom
bump_go_jose

Conversation

@lbajolet-hashicorp
Copy link
Copy Markdown
Contributor

Since v4.0.1 of the go-jose module is vulnerable to CVE-2025-22868, we bump to v4.0.5 to remediate this.

Note: while the dependency is vulnerable to this CVE, the attack is not realistic for Packer, hence this was not a problem in the first place, but bumping the dependency to make scanners happy.

Since v4.0.1 of the go-jose module is vulnerable to CVE-2025-22868, we
bump to v4.0.5 to remediate this.

Note: while the dependency is vulnerable to this CVE, the attack is not
realistic for Packer, hence this was not a problem in the first place,
but bumping the dependency to make scanners happy.
@lbajolet-hashicorp lbajolet-hashicorp added tech-debt Issues and pull requests related to addressing technical debt or improving the codebase security labels Mar 28, 2025
@lbajolet-hashicorp lbajolet-hashicorp requested a review from a team as a code owner March 28, 2025 19:51
@lbajolet-hashicorp lbajolet-hashicorp merged commit 9800105 into main Mar 28, 2025
9 checks passed
@lbajolet-hashicorp lbajolet-hashicorp deleted the bump_go_jose branch March 28, 2025 20:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

security tech-debt Issues and pull requests related to addressing technical debt or improving the codebase

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants