Skip to content

Conversation

ajayk
Copy link

@ajayk ajayk commented Jan 31, 2024

Moves from unmaintained go-git.v4 to go-git.v5 and as the go-git.v4 has a critical CVE https://pkg.go.dev/vuln/GO-2024-2466

and updates golang.org/x/net and x/crypto and circl to latest versions bunch of cve's reported in older versions

@ajayk ajayk changed the title moce from go-git.v4 to go-git.v5 move from go-git.v4 to go-git.v5 Jan 31, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant