Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Recommend moving to v2 for github.com/grpc-ecosystem/grpc-gateway #45

Closed
awilcots opened this issue Mar 23, 2022 · 0 comments · Fixed by #46
Closed

Recommend moving to v2 for github.com/grpc-ecosystem/grpc-gateway #45

awilcots opened this issue Mar 23, 2022 · 0 comments · Fixed by #46
Assignees

Comments

@awilcots
Copy link

Due to a dependabot alert I’ve noticed that this package is using an older version of github.com/grpc-ecosystem/grpc-gateway resulting in usage of a vulnerable version of gopkg.in/yaml.v2 version v2.2.3, CVE-2019-11254. Did you have any plans to update to github.com/grpc-ecosystem/grpc-gateway/v2, addressing the security concern or otherwise?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants