-
Notifications
You must be signed in to change notification settings - Fork 471
Open
Description
Please address the security bug identified by Snyk:
https://security.snyk.io/vuln/SNYK-GOLANG-GITHUBCOMDISINTEGRATIONIMAGING-5880692
On a related note, GitHub dependabot claims that updating the transient dependency golang.org/x/image to v0.10.0 or higher is sufficient. However, Snyk continues to report this disintegration/imaging module as vulnerable.
I don't have enough information to determine whether GitHub or Snyk is more accurate. Someone should clarify the situation.
If necessary, fork this repository.
Metadata
Metadata
Assignees
Labels
No labels