git-credential-github-apps icon indicating copy to clipboard operation
git-credential-github-apps copied to clipboard

Bump github.com/bradleyfalzon/ghinstallation/v2 to v2.7.0

Open avijoenil opened this issue 2 years ago • 1 comments

Because of the vulnerabilites found in the following scan. The ghinstallation dependency is bumped to 2.7.0

avijoenil avatar Sep 14 '23 11:09 avijoenil

To be specific, this addressed the CVE-2022-39304 and CVE-2020-26160 security vulnerabilities.

For those that find this PR. Note that I went ahead and forked this repo and merged this fix and others at Avinode/git-credential-github-apps. We started using this Git credentials provider and needed these security related patches applied in order to continue utilizing it. We have also published a v1.2.0 release there.

I don't want to step on anyone's toes, and will gladly close down the fork if this repo comes back to life.

Thanks for this fix! We needed it!

pedrohdz avatar Sep 14 '23 14:09 pedrohdz