Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Patch CVE-2024-24792 #209

Merged
merged 1 commit into from
Jul 1, 2024
Merged

Patch CVE-2024-24792 #209

merged 1 commit into from
Jul 1, 2024

Conversation

ingve
Copy link
Contributor

@ingve ingve commented Jul 1, 2024

Fixes

=== Symbol Results ===

Vulnerability #1: GO-2024-2937
    Panic when parsing invalid palette-color images in golang.org/x/image
  More info: https://pkg.go.dev/vuln/GO-2024-2937
  Module: golang.org/x/image
    Found in: golang.org/x/image@v0.16.0
    Fixed in: golang.org/x/image@v0.18.0
    Example traces found:
      #1: internal/docs/docs.go:48:27: docs.RenderMarkdown calls term.Render, which eventually calls tiff.Decode

Your code is affected by 1 vulnerability from 1 module.

@ingve ingve requested a review from andebor July 1, 2024 07:00
@ingve ingve merged commit 45eb768 into master Jul 1, 2024
2 checks passed
@ingve ingve deleted the chore/24-183-fix-govulncheck-vulns branch July 1, 2024 08:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants