gvisor icon indicating copy to clipboard operation
gvisor copied to clipboard

fix(sec): upgrade golang.org/x/net to 0.7.0

Open dack-su opened this issue 2 years ago • 3 comments

What happened?

There are 1 security vulnerabilities found in golang.org/x/net v0.5.0

What did I do?

Upgrade golang.org/x/net from v0.5.0 to 0.7.0 for vulnerability fix

What did you expect to happen?

Ideally, no insecure libs should be used.

How can we automate the detection of these types of issues?

By using the GitHub Actions configurations provided by murphysec, we can conduct automatic code security checks in our CI pipeline.

The specification of the pull request

PR Specification from OSCS

dack-su avatar Sep 07 '23 10:09 dack-su

Thanks for your pull request! It looks like this may be your first contribution to a Google open source project. Before we can look at your pull request, you'll need to sign a Contributor License Agreement (CLA).

View this failed invocation of the CLA check for more information.

For the most up to date status, view the checks section at the bottom of the pull request.

google-cla[bot] avatar Sep 07 '23 10:09 google-cla[bot]

thanks for reporting the vulnerability, would you mind signing the CLA?

milantracy avatar Sep 07 '23 17:09 milantracy

A friendly reminder that this PR had no activity for 120 days.

github-actions[bot] avatar Jan 06 '24 00:01 github-actions[bot]

This PR has been closed due to lack of activity.

github-actions[bot] avatar Apr 06 '24 00:04 github-actions[bot]