encore.dev icon indicating copy to clipboard operation
encore.dev copied to clipboard

This repository contains the Encore's Runtime API contract, which Encore applications are built against.

Results 5 encore.dev issues
Sort by recently updated
recently updated
newest added

Bumps [github.com/jackc/pgx/v5](https://github.com/jackc/pgx) from 5.2.0 to 5.5.4. Changelog Sourced from github.com/jackc/pgx/v5's changelog. 5.5.4 (March 4, 2024) Fix CVE-2024-27304 SQL injection can occur if an attacker can cause a single query or...

dependencies

Bumps [golang.org/x/crypto](https://github.com/golang/crypto) from 0.0.0-20220829220503-c86fa9a7ed90 to 0.17.0. Commits See full diff in compare view [![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=golang.org/x/crypto&package-manager=go_modules&previous-version=0.0.0-20220829220503-c86fa9a7ed90&new-version=0.17.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter...

dependencies

just updating version, no breaking changes, updates indirect dependency golang.org/x/text as v0.3.8 has security vulnerability https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-38561

Hi team, Context: I realize this repository only holds the contract for development purposes, but some vulnerability scanners - such as Snyk - light up when scanning this, and updating...