Skip to content

Bump dependencies to address CVE-2022-41723 #272

@markapruett

Description

@markapruett

A trivy scan of external-resizer images lists this project as vulnerable to CVE-2022-41723 because of the indirect dependency of golang.org/x/net at v0.4.0.

I see in master the x/net is at 0.7.0 which would resolve the alerts. Is a new release planned shortly?

Thanks!

Metadata

Metadata

Assignees

No one assigned

    Labels

    lifecycle/rottenDenotes an issue or PR that has aged beyond stale and will be auto-closed.

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions