Skip to content

Bumping x/crypto to 0.31.0 #265

@nekoffski

Description

@nekoffski

Our internal code scanner is complaining about the x/crypto == v.0.24.0 because of CVE-2024-45337. Do you plan bumping the lib version by any chance? I fully understand that since you don't use the vulnerable SSH module it is very-low priority or even not considered to do at all but I'm just exploring my options to waive the detected issue.

Thanks.

https://www.cve.org/CVERecord?id=CVE-2024-45337

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions