Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade dependencies #36

Merged
merged 1 commit into from
Dec 17, 2024
Merged

Upgrade dependencies #36

merged 1 commit into from
Dec 17, 2024

Conversation

dfangl
Copy link
Member

@dfangl dfangl commented Dec 12, 2024

Motivation

golang.org/x/net v0.18.0 has a moderate CVE reported which some customer tooling reports as high: https://avd.aquasec.com/nvd/2023/cve-2023-45288/ , GHSA-4v7x-pqxf-cx7m

Updating the xray daemon dependency also upgrades golang.org/x/net.

Related to localstack/localstack#12011

Changes

  • Upgrade github.com/aws/aws-xray-daemon and its dependencies
  • No behavioral changes expected

@dfangl dfangl requested a review from joe4dev December 12, 2024 14:55
@dfangl dfangl merged commit 0b2b5be into localstack Dec 17, 2024
1 check passed
@dfangl dfangl deleted the upgrade-dependencies branch December 17, 2024 15:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants