Skip to content

Conversation

@Xe
Copy link

@Xe Xe commented Jan 31, 2023

Signed-off-by: Xe Iaso xe@tailscale.com

Signed-off-by: Xe Iaso <xe@tailscale.com>
@Xe Xe requested a review from nhooyr as a code owner January 31, 2023 17:07
@marcus-vw
Copy link

Can we merge the PR. The changes are reasonable.

@komuw
Copy link

komuw commented Feb 25, 2023

If we run https://pkg.go.dev/golang.org/x/vuln/cmd/govulncheck on this repository, it does not list it as been affected by CVE-2020-28483. And yes, that CVE does exist in its database; https://pkg.go.dev/vuln/GO-2021-0052 .
There are a lot of vuln. scanners out there that raise an alert just because a dependency exists(and at a certain version) without analysing whether the actual defect is exercised in the codebase.

@nhooyr
Copy link
Contributor

nhooyr commented Mar 7, 2023

See #297

@nhooyr nhooyr closed this Mar 7, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

4 participants