Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fixes known security vulnerabilities in go-git #29314

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

tsaarni
Copy link
Contributor

@tsaarni tsaarni commented Jan 8, 2025

This PR bumps the version of build-time dependency go-git to fix following known security vulnerabilities

@tsaarni tsaarni requested a review from a team as a code owner January 8, 2025 12:52
@tsaarni tsaarni requested a review from kitography January 8, 2025 12:52
@tsaarni
Copy link
Contributor Author

tsaarni commented Jan 8, 2025

Test "Protobuf generate delta" seems to fail since version of protoc-gen-go@latest has changed since last time, requiring re-generation of go code with make proto. I did not include those changes in this PR though. I can do that if wanted.

Copy link
Contributor

@divyaac divyaac left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good! Just one thing - no need to add a changelog for version bumps. After it is a removed, I will approve it.

@tsaarni
Copy link
Contributor Author

tsaarni commented Jan 28, 2025

I've now removed the changelog file and applied latest go-git which had changed to v5.13.2 (was v5.13.1 last time) and ran go mod tidy.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants