Skip to content

CVE-2025-21613 in github.com/go-git/go-git/v5 v5.11.0 #473

Open
DataWiseHQ/grule-rule-engine
#2
@bvwells

Description

@bvwells

Describe the bug

grule-rule-engine has a dependency on github.com/go-git/go-git/v5 v5.11.0 which is affected by CVE-2025-21613 (see https://nvd.nist.gov/vuln/detail/CVE-2025-21613). It would be great if this dependency could be updated and a new version of the module published. Obviously this can be managed through the use of module replace statements, but it is nice not to have to. I'm more than happy to submit a fix.

Thanks for the great module!

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions