Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fix vulnerability: GO-2024-2947 #78

Merged
merged 1 commit into from
Jul 2, 2024
Merged

Fix vulnerability: GO-2024-2947 #78

merged 1 commit into from
Jul 2, 2024

Conversation

alexandear
Copy link
Owner

Vulnerability #1: GO-2024-2947
    Leak of sensitive information to log files in
    github.com/hashicorp/go-retryablehttp
  More info: https://pkg.go.dev/vuln/GO-2024-2947
  Module: github.com/hashicorp/go-retryablehttp
    Found in: github.com/hashicorp/[email protected]
    Fixed in: github.com/hashicorp/[email protected]
    Example traces found:
Error:       #1: internal/gitlab.go:37:51: internal.GitLab.CurrentUser calls gitlab.UsersService.ListEmails, which eventually calls retryablehttp.Client.Do

@alexandear alexandear enabled auto-merge (squash) July 2, 2024 18:12
@alexandear alexandear merged commit 85a35ef into main Jul 2, 2024
5 of 6 checks passed
@alexandear alexandear deleted the fix-GO-2024-2947 branch July 2, 2024 18:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

1 participant