We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? # to your account
Describe the bug
Summary from Trivy scan:
Vulnerability information: +--------------------------------+-----------------------------+----------+-------------------+---------------+----------------------------------------------------------------------------+--------------------------------------------+ | Type | Library | Severity | Installed Version | Fixed Version | Summary | More Details | +--------------------------------+-----------------------------+----------+-------------------+---------------+----------------------------------------------------------------------------+--------------------------------------------+ | bin/argo-events (gobinary) | golang.org/x/crypto (None) | CRITICAL | v0.29.0 | 0.31.0 | Applications and libraries which misuse the ServerConfig.PublicKeyCall ... | https://avd.aquasec.com/nvd/cve-2024-45337 | | usr/local/bin/argo (gobinary) | golang.org/x/crypto (None) | CRITICAL | v0.24.0 | 0.31.0 | Applications and libraries which misuse the ServerConfig.PublicKeyCall ... | https://avd.aquasec.com/nvd/cve-2024-45337 | +--------------------------------+-----------------------------+----------+-------------------+---------------+----------------------------------------------------------------------------+--------------------------------------------+
To Reproduce
N/A
Expected behavior
No CRITICAL vulnerabilities found,
Screenshots N/A
Environment (please complete the following information):
Additional context N/A
Message from the maintainers:
If you wish to see this enhancement implemented please add a 👍 reaction to this issue! We often sort issues this way to know what to prioritize.
The text was updated successfully, but these errors were encountered:
The package has been upgraded in #3390
Would it be possible to release v1.9.4 as a security patch?
Sorry, something went wrong.
Fixed in argo-events binary, but no argo binary available yet.
argo
No branches or pull requests
Describe the bug
Summary from Trivy scan:
To Reproduce
N/A
Expected behavior
No CRITICAL vulnerabilities found,
Screenshots
N/A
Environment (please complete the following information):
Additional context
N/A
Message from the maintainers:
If you wish to see this enhancement implemented please add a 👍 reaction to this issue! We often sort issues this way to know what to prioritize.
The text was updated successfully, but these errors were encountered: