You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
gommon v0.3.0 uses github.com/stretchr/[email protected] which in turns uses gopkg.in/[email protected] which suffers a severe CVE long fixed since there is at least a v2.2.8 and even v2.4.0.
By simply, upgrading the yaml dependency, this would avoid having the CVE reported by security scanning tools (lke sonatype).
The text was updated successfully, but these errors were encountered:
Simply upgrade depency for github.com/stretchr/testify from v1.40 to v1.7.0 which in turns uses gopkg.in/yaml.v3 then publish a v0.4.0/v.0.3.1 which will be usable by echo project
gommon v0.3.0 uses github.com/stretchr/[email protected] which in turns uses gopkg.in/[email protected] which suffers a severe CVE long fixed since there is at least a v2.2.8 and even v2.4.0.
By simply, upgrading the yaml dependency, this would avoid having the CVE reported by security scanning tools (lke sonatype).
The text was updated successfully, but these errors were encountered: