Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bumps HashiCorp SDK library #162

Merged
merged 2 commits into from
Nov 26, 2024
Merged

Bumps HashiCorp SDK library #162

merged 2 commits into from
Nov 26, 2024

Conversation

luispresuelVenafi
Copy link
Contributor

  • Bumps HashiCorp SDK library to update dependency github.com/docker/docker which hold vulnerability with a docker dependency as per reported by our bot:

A security vulnerability has been detected in certain versions of Docker Engine, which could allow an attacker to bypass authorization plugins (AuthZ) under specific circumstances. The base likelihood of this being exploited is low. This advisory outlines the issue, identifies the affected versions, and provides remediation steps for impacted users.

This will upgrade github.com/docker/docker from 24.0.7+incompatible to 25.0.6+incompatible, minium version that has the bug resolved

@luispresuelVenafi luispresuelVenafi merged commit ad6fd9d into master Nov 26, 2024
3 checks passed
@luispresuelVenafi luispresuelVenafi deleted the bump-sdk-version branch November 26, 2024 16:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants