Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Wiz: Upgrade multiple dependencies (resolves 20 findings) #1

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

wiz-1a0396c292[bot]
Copy link

@wiz-1a0396c292 wiz-1a0396c292 bot commented Mar 9, 2025

Wiz Remediation Pull Request Banner

Wiz has created this PR to fix 20 findings detected in this project

Changes were made to the following file(s):

  • /go.mod

Vulnerabilities:

Component Findings Locations
github.com/hashicorp/go-retryablehttp
0.7.1 → 0.7.7
Medium CVE-2024-6104 /go.mod
github.com/jackc/pgproto3/v2
2.3.0 → 2.3.3
High GHSA-7jwh-3vrq-q3m8 /go.mod
github.com/jackc/pgx/v4
4.16.1 → 4.18.2
Critical CVE-2024-27304
High CVE-2024-27289
/go.mod
golang.org/x/crypto
0.0.0-20210921155107-089bfa567519 → 0.31.0
Critical CVE-2024-45337
High CVE-2021-43565
High CVE-2022-27191
Medium CVE-2023-48795
/go.mod
golang.org/x/net
0.0.0-20220520000938-2e3eb7b945c2 → 0.33.0
High CVE-2022-27664
High CVE-2022-41723
High CVE-2023-39325
High CVE-2023-45288
High CVE-2023-44487
Medium CVE-2022-41717
Medium CVE-2024-45338
Medium CVE-2023-3978
/go.mod
golang.org/x/sys
0.0.0-20211216021012-1d35b9e2eb4e → 0.0.0-20220412211240-33da011f77ad
Medium CVE-2022-29526 /go.mod
golang.org/x/text
0.3.7 → 0.3.8
High CVE-2022-32149 /go.mod
google.golang.org/protobuf
1.28.0 → 1.33.0
High CVE-2024-24786 /go.mod
gopkg.in/yaml.v3
3.0.0-20210107192922-496545a6307b → 3.0.0-20220521103104-8f96da9f5d5e
High CVE-2022-28948 /go.mod

To detect these findings earlier in the dev lifecycle, try using Wiz Code VS Code Extension.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants