Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

update ggcr to HEAD to eliminate (false) vuln finding #1044

Merged
merged 1 commit into from
Nov 12, 2021

Conversation

dekkagaijin
Copy link
Member

GGCR does not rely on the vulnerable codepath, but this PR updates the indirect dependency to avoid findings related to CVE-2021-41092

NONE

@dlorenc dlorenc merged commit f1ec3a6 into sigstore:main Nov 12, 2021
@github-actions github-actions bot added this to the v1.4.0 milestone Nov 12, 2021
@dekkagaijin dekkagaijin deleted the ggcr branch November 12, 2021 21:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants