Skip to content

Dependency oras-go is pinned to a known vulnerable version #1361

Description

@suidpit

What is not working as expected?

The project is pinning a vulnerable version of the https://github.com/oras-project/oras-go dependency.

The pinned version is v2.6.0, which is vulnerable to multiple known vulnerabilities (see https://github.com/oras-project/oras-go/security).

What did you expect to happen?

The project should automatically detect and bump up vulnerable dependencies.

How can we reproduce it?

Manually inspecting the go.mod file is enough.

Describe your environment

Cloned and built from git.

What is the version of your Notation CLI or Notation Library?

This was observed in latest (2c82269).

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't workingtriageNeed to triage

    Type

    No type

    Projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions