Skip to content

Conversation

@HDYA
Copy link
Contributor

@HDYA HDYA commented Oct 31, 2025

What is the problem I am trying to address?

CVE GHSA-mh63-6h87-95cp from github.com/golang-jwt/jwt/v4 (Go) < 4.5.2 in binary git-credential-github-app used in cmd/proxy/Dockerfile

How is the fix applied?

According to commit 41a5848431cb0d004c0aed2c3352b0e8cfc0d490 from repository bdellegrazie/git-credential-github-app, version tag v0.3.4 started to ship with this patch

What GitHub issue(s) does this PR fix or close?

N/A

Fixes #

N/A

@HDYA HDYA requested a review from a team as a code owner October 31, 2025 09:45
Copy link
Member

@DrPsychick DrPsychick left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you for your contribution!

@DrPsychick DrPsychick merged commit d64bfc6 into gomods:main Oct 31, 2025
14 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants