You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
@akoshok1 Our version of gopkg.in/yaml.v3 is v3.0.1. It should be newer than the version 3.0.0-20220521103104-8f96da9f5d5e in the CVE GHSA-hp87-p4gw-j4gq. So I think this CVE does not affect out newest version (3.4.x).
Is there an existing issue for this?
Does this enhancement require public documentation?
Problem Statement
Current version of KIC runs go 1.23.2 this has at least 3 open CVEs
CVE-2024-45336
CVE-2022-28948
CVE-2024-45341
Proposed Solution
Please update go version to 1.23.5 to address CVEs
Additional information
No response
Acceptance Criteria
No response
The text was updated successfully, but these errors were encountered: