Skip to content

Conversation

@klaidliadon
Copy link
Contributor

@klaidliadon klaidliadon commented May 20, 2024

This PR updates the src-d/go-git dependency, which is archived in favor of go-git/go-git.
The current version suffers from this vulnerability.

Copy link

@VojtechVitek VojtechVitek left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

"strings"

"github.com/go-git/go-billy/v5/osfs"
git "github.com/go-git/go-git/v5"

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Screen Shot 2024-05-20 at 10 52 06 AM

posener added a commit that referenced this pull request May 20, 2024
Thanks for submitting #37. I decided to do the commit myself just to make sure there is nothing injected there. I updated according to your instructions and ran the go mod tidy command myself.

Sorry for not merging your commit, but there is a lot of cryptic updates there that I wanted to make sure were made with the  command.
@posener
Copy link
Owner

posener commented May 20, 2024

Hey, I pushed this update to master. Sorry for not merging this commit, I wanted to run the go mod tidy command myself (there are a lot of cryptic updates in the go.sum file.

@posener posener closed this May 20, 2024
@VojtechVitek
Copy link

@posener great, thank you!

@klaidliadon would you mind fixing the CI (by upgrading Go versions at https://github.com/posener/gitfs/blob/master/.github/workflows/test.yml#L11-L13), so Eyal can release a new git tag, please?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants