Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump go-libp2p to address quic-go CVE #659

Merged
merged 1 commit into from
Dec 6, 2024

Conversation

dereknola
Copy link
Contributor

Instead of #658, bump the correct direct dependency which uses the newer version of quic-go.

Copy link

codecov bot commented Dec 5, 2024

Codecov Report

All modified and coverable lines are covered by tests ✅

Copy link
Member

@phillebaba phillebaba left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks this is a better option.

@phillebaba phillebaba merged commit b682a7f into spegel-org:main Dec 6, 2024
7 checks passed
mamccorm added a commit to wolfi-dev/os that referenced this pull request Dec 12, 2024
Automated commit attempted to bump quic-go dependnecy to remediate
GHSA-px8v-pp82-rcvr. However the latest version of quic-go, also
required another dependency (go-libp2p) to be upgraded.

The good news, upstream already made similar changes in main as part of:
spegel-org/spegel#659, they just haven't made it
into a release yet.

---------------


spegel/0.0.27-r0: fix GHSA-px8v-pp82-rcvr

Advisory data:
https://github.com/wolfi-dev/advisories/blob/main/spegel.advisories.yaml

---------

Signed-off-by: Mark McCormick <[email protected]>
Co-authored-by: octo-sts[bot] <[email protected]>
Co-authored-by: Mark McCormick <[email protected]>
@dereknola dereknola deleted the bump_go-libp2p branch January 8, 2025 18:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants