Skip to content

Fix CVE-2024-28180 #4720

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 1 commit into from
Apr 24, 2024
Merged

Fix CVE-2024-28180 #4720

merged 1 commit into from
Apr 24, 2024

Conversation

atoulme
Copy link
Contributor

@atoulme atoulme commented Apr 24, 2024

Description:
Fix CVE-2024-28180 by upgrading github.com/hashicorp/vault-plugin-auth-gcp to v0.17.0, dropping the dependency gopkg.in/square/go-jose.v2 v2.6.0

@atoulme atoulme requested review from a team as code owners April 24, 2024 01:18
@jinja2 jinja2 merged commit 7a60d21 into main Apr 24, 2024
27 checks passed
@jinja2 jinja2 deleted the fix_CVE-2024-28180 branch April 24, 2024 03:24
@github-actions github-actions bot locked and limited conversation to collaborators Apr 24, 2024
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants