Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade go-restful dependency version due to CVE 2022-1996 vulnerability #2130

Closed
MahnoorAsghar opened this issue Jul 7, 2022 · 3 comments
Closed
Assignees
Labels
enhancement New feature or request

Comments

@MahnoorAsghar
Copy link

MahnoorAsghar commented Jul 7, 2022

Summary

I have an issue with a argoproj/argo-rollouts dependency version: go-restful v2.9.5. This is being imported by argo-rollouts, and the latest release of argo-rollouts uses this version too. I want to get this upgraded to go-restful v3.8.0.

Use Cases

I am using argo-rollouts in my repository, and my repository is getting CVE-2022-1996 vulnerability brought by go-restful library v2.9.5.


Message from the maintainers:

Impacted by this bug? Give it a 👍. We prioritize the issues with the most 👍.

@zachaller
Copy link
Collaborator

fixed in #2136

@MahnoorAsghar
Copy link
Author

MahnoorAsghar commented Jul 13, 2022

fixed in #2136
@zachaller
When will this fix be released? The latest argo-rollouts release was in May

@zachaller
Copy link
Collaborator

We are working on trying to releasing a 1.3 RC in the next 2 to 4 weeks.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

3 participants