Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

#1261 Update go-getter dependency version #1262

Merged
merged 1 commit into from
Mar 16, 2023
Merged

Conversation

denis256
Copy link
Member

@denis256 denis256 commented Mar 16, 2023

Description

Updated go-getter dependency to avoid issues from malware scanners.

Fixes #1261.

TODOs

Read the Gruntwork contribution guidelines.

  • Update the docs.
  • Run the relevant tests successfully, including pre-commit checks.
  • Ensure any 3rd party code adheres with our license policy or delete this line if its not applicable.
  • Include release notes. If this PR is backward incompatible, include a migration guide.

Release Notes (draft)

Updated go-getter dependency to 1.7.1

Migration Guide

@denis256 denis256 requested a review from zackproser as a code owner March 16, 2023 05:05
@tschechniker
Copy link

+1 same issue here. Hard blocker for us

Copy link
Contributor

@MoonMoon1919 MoonMoon1919 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@denis256 denis256 merged commit 5409026 into master Mar 16, 2023
@denis256 denis256 deleted the bug/go-getter-1261 branch March 16, 2023 17:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

go-getter v1.7.0 has a zip bomb and it is categorized as malware
3 participants