From d4264b99e4bf3abd403ba35aaee5f90e4b77b57f Mon Sep 17 00:00:00 2001 From: "octo-sts[bot]" <157150467+octo-sts[bot]@users.noreply.github.com> Date: Sat, 21 Dec 2024 08:44:14 +0000 Subject: [PATCH] Adding Advisory GHSA-w32m-9786-jp63 for scorecard (#10976) Co-authored-by: octo-sts[bot] <157150467+octo-sts@users.noreply.github.com> --- scorecard.advisories.yaml | 18 ++++++++++++++++++ 1 file changed, 18 insertions(+) diff --git a/scorecard.advisories.yaml b/scorecard.advisories.yaml index a18285f968..fb621a53ef 100644 --- a/scorecard.advisories.yaml +++ b/scorecard.advisories.yaml @@ -376,6 +376,24 @@ advisories: data: fixed-version: 4.13.1-r4 + - id: CGA-q55h-v2fp-9jw2 + aliases: + - CVE-2024-45338 + - GHSA-w32m-9786-jp63 + events: + - timestamp: 2024-12-21T08:11:53Z + type: detection + data: + type: scan/v1 + data: + subpackageName: scorecard + componentID: 0aaf9e37704a4c05 + componentName: golang.org/x/net + componentVersion: v0.27.0 + componentType: go-module + componentLocation: /usr/bin/scorecard + scanner: grype + - id: CGA-r9v9-3h8g-vvg8 aliases: - GHSA-m425-mq94-257g