Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Please recompile release with newer Go1.20 (multiple security warnings) #96

Open
sseide opened this issue Nov 6, 2023 · 1 comment
Open

Comments

@sseide
Copy link
Contributor

sseide commented Nov 6, 2023

Hello,

Current release 0.12.4 throws multiple security warnings by some scanner. Even when they are not really a problems (e.g. only compile time or if used server side) it would be great to just recompile remco with a newer golang version to address these warnings. Otherwise all projects using this binary need to whitelist all of these findings:

Thanks,
Stefan Seide

@ahormazabal
Copy link

ahormazabal commented Mar 14, 2024

+1 here!!! We;re having some CVEs reported over remco, specifically GHSA-qppj-fm5r-hxr3

I see these fixes are already available in the main branch. Can we get a new release with those fixes?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants