-
Notifications
You must be signed in to change notification settings - Fork 207
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Security Vulnerability Upgrading golang.org/x/text #287
Conversation
Hello @KaylaNguyen I'm a new collaborator to this repo and I would like to get some traction on this request, to solve an indirect dependency. Please if you are not the best point of contact, can you point me in the right direction? Thanks |
Thanks for the pr! @jinglundong is the POC for this repo now. Jinglun can you take a look? Thanks! |
Thank for looping me in, Kayla. This repo is the source of truth. I will review and release this hopefully this week. |
Hello @jinglundong Thanks for reviewing this PR. Please notice I had an issue with my GPG key I just fixed but is causing this PR to be re-approved. Sorry for any inconvenience. Also when do you estimate this change will be released? Thanks |
No worries. I approved the workflow that runs the tests. Let's see how it goes. |
Hello @jinglundong Do you have an estimate when this change will be released? Thanks |
I created a new release (with tag v2.0.2). Based on my reading of our playbook, that's all we need to release it. Please change the entry in go.mod to |
Request to update golang.org/x/text prior to v0.3.6 library to non-vulnerable version v0.3.7.
CVE-2020-14040
CVE-2021-38561