build(deps): bump golang.org/x/crypto from 0.27.0 to 0.31.0 by dependabot[bot] · Pull Request #12377 · docker/compose (original) (raw)

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service andprivacy statement. We’ll occasionally send you account related emails.

Already on GitHub?Sign in to your account

Conversation3 Commits1 Checks29 Files changed

Conversation

This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.Learn more about bidirectional Unicode characters

[ Show hidden characters]({{ revealButtonHref }})

[dependabot[bot]](/apps/dependabot)

Bumps golang.org/x/crypto from 0.27.0 to 0.31.0.

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

@dependabot

@lpradel

ndeloof

@ndeloof ndeloof deleted the dependabot/go_modules/golang.org/x/crypto-0.31.0 branch

December 12, 2024 18:12

@BenTheElder

@thaJeztah

The CVE is a false positive for compose; the compose code is not affected by this CVE;

git describe --tags
v2.31.0

govulncheck -show verbose ./...
Scanning your code and 1165 packages across 180 dependent modules for known vulnerabilities...

Fetching vulnerabilities from the database...

Checking the code against the vulnerabilities...

=== Symbol Results ===

No vulnerabilities found.

=== Package Results ===

Vulnerability #1: GO-2024-3321
    Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in
    golang.org/x/crypto
  More info: https://pkg.go.dev/vuln/GO-2024-3321
  Module: golang.org/x/crypto
    Found in: golang.org/x/crypto@v0.27.0
    Fixed in: golang.org/x/crypto@v0.31.0

=== Module Results ===

No other vulnerabilities found.

Your code is affected by 0 vulnerabilities.
This scan also found 1 vulnerability in packages you import and 0
vulnerabilities in modules you require, but your code doesn't appear to call
these vulnerabilities.

tmeijn pushed a commit to tmeijn/dotfiles that referenced this pull request

Dec 20, 2024

@tmeijn