Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2025-21613 in github.com/go-git/go-git/v5 v5.11.0 #473

Open
bvwells opened this issue Feb 11, 2025 · 0 comments · Fixed by DataWiseHQ/grule-rule-engine#2
Open

CVE-2025-21613 in github.com/go-git/go-git/v5 v5.11.0 #473

bvwells opened this issue Feb 11, 2025 · 0 comments · Fixed by DataWiseHQ/grule-rule-engine#2

Comments

@bvwells
Copy link

bvwells commented Feb 11, 2025

Describe the bug

grule-rule-engine has a dependency on github.com/go-git/go-git/v5 v5.11.0 which is affected by CVE-2025-21613 (see https://nvd.nist.gov/vuln/detail/CVE-2025-21613). It would be great if this dependency could be updated and a new version of the module published. Obviously this can be managed through the use of module replace statements, but it is nice not to have to. I'm more than happy to submit a fix.

Thanks for the great module!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

1 participant