-
Couldn't load subscription status.
- Fork 148
Closed as not planned
Labels
lifecycle/rottenDenotes an issue or PR that has aged beyond stale and will be auto-closed.Denotes an issue or PR that has aged beyond stale and will be auto-closed.
Description
A trivy scan of external-resizer images lists this project as vulnerable to CVE-2022-41723 because of the indirect dependency of golang.org/x/net at v0.4.0.
I see in master the x/net is at 0.7.0 which would resolve the alerts. Is a new release planned shortly?
Thanks!
richgiuli, gtxu and kschumy
Metadata
Metadata
Assignees
Labels
lifecycle/rottenDenotes an issue or PR that has aged beyond stale and will be auto-closed.Denotes an issue or PR that has aged beyond stale and will be auto-closed.