Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fixes CVE-2023-49569 #401

Merged
merged 1 commit into from
Apr 2, 2024
Merged

Conversation

antoinerg
Copy link
Contributor

@antoinerg antoinerg commented Mar 27, 2024

Fixes CVE-2023-49569

Fixed by upgrading go-git:

go get github.com/go-git/go-git/v5@v5.11.0

@paketo-bot paketo-bot added the semver:patch A change requiring a patch version bump label Mar 27, 2024
@antoinerg antoinerg marked this pull request as ready for review March 27, 2024 23:57
@antoinerg antoinerg requested a review from a team as a code owner March 27, 2024 23:57
@antoinerg antoinerg changed the title go get github.com/go-git/go-git/v5@v5.11.0 fixes CVE-2023-49569 Mar 27, 2024
@thitch97 thitch97 merged commit e5c5dee into paketo-buildpacks:main Apr 2, 2024
11 of 12 checks passed
@antoinerg antoinerg deleted the upgr-go-git branch April 15, 2024 19:14
@antoinerg
Copy link
Contributor Author

Thank you @thitch97 🙇

When can we expect a new release with this fix security fix?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
semver:patch A change requiring a patch version bump
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants