Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2023-44487: Bump grpc for indirect usages #68

Closed
wants to merge 1 commit into from

Commits on Nov 13, 2023

  1. CVE-2023-44487: Bump grpc for indirect usages

    We still have potential indirect uses
    of affected google.golang.org/grpc.
    For example cloud.google.com/go v0.97.0 (and many more according Synk).
    
    Hence bump grpc to a fixed version.
    
    GHSA-qppj-fm5r-hxr3
    
    Signed-off-by: Or Shoval <oshoval@redhat.com>
    oshoval committed Nov 13, 2023
    Configuration menu
    Copy the full SHA
    b0cb370 View commit details
    Browse the repository at this point in the history