You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Describe the bug CVE-2024-34156 has been published against the stdlib lib in go binaries and is found by trivy in docker image v2.7 which uses go1.22.5
It is recommended to fix with the patch go1.22.7 or the very recent minor update go1.23.1. Which one would you prefer to go with?
It is also the question, wether the package encoding/gob is used in krakend-ce or not.
Commands used trivy image -v devopsfaith/krakend:2.7
Expected behavior
No high/critical vulnerability report.
The text was updated successfully, but these errors were encountered:
Environment info:
Describe the bug
CVE-2024-34156 has been published against the stdlib lib in go binaries and is found by trivy in docker image v2.7 which uses go1.22.5
It is recommended to fix with the patch go1.22.7 or the very recent minor update go1.23.1. Which one would you prefer to go with?
It is also the question, wether the package encoding/gob is used in krakend-ce or not.
Commands used
trivy image -v devopsfaith/krakend:2.7
Expected behavior
No high/critical vulnerability report.
The text was updated successfully, but these errors were encountered: