HeavyHorst / remco

remco is a lightweight configuration management tool

Home Page:https://heavyhorst.github.io/remco/

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Please publish new version with your updated dependencies

sseide opened this issue · comments

commented

Hello,

can you please publish a new version with all the updated dependencies you already have? They will silence security scanner because a lot of different vulnerable dependencies are updated now.

Thanks in advance,
S. Seide

Hello,
We also are being challenged on our use of this tool, as the current version of golang is subject of many vulnerabilities, some of these include:
CVE-2022-41716
CVE-2022-32190
CVE-2022-38149
CVE-2022-32149

Is there an update path to provide a newer version with updated dependencies?

Sorry for the delay. I will create a new Release once Go 1.20.5 is released next week.

https://groups.google.com/g/golang-announce/c/1AItFMBjrfw/m/jgn2iuoFAgAJ?utm_medium=email&utm_source=footer

commented

Yes - and current release has following problems too - parts are already fixed with current master.
Might be fixed with GoLang update too (i have not checked)

@sseide these are all fixed already in master.
Will cut a new release later today.