From 83ef52f98269ba98a4e2e50a4b83c5e60bb69210 Mon Sep 17 00:00:00 2001 From: "HeraldBot[bot]" <149080493+heraldbot[bot]@users.noreply.github.com> Date: Thu, 7 Nov 2024 09:06:54 +0000 Subject: [PATCH 1/3] Remediate Nancy findings --- .nancy-ignore | 1 + 1 file changed, 1 insertion(+) diff --git a/.nancy-ignore b/.nancy-ignore index 3c38d91..e4c7841 100644 --- a/.nancy-ignore +++ b/.nancy-ignore @@ -1,3 +1,4 @@ CVE-2024-0874 until=2024-11-20 # github.com/coredns/coredns@v1.10.1 CVE-2023-28452 until=2024-11-20 # github.com/coredns/coredns@v1.10.1 CVE-2023-30464 until=2024-11-20 # github.com/coredns/coredns@v1.10.1 +CVE-2024-51744 until=2024-12-07 # github.com/golang-jwt/jwt/v4@v4.2.0 From bf6ba35d007c97e60b34972a893c0a3591530632 Mon Sep 17 00:00:00 2001 From: "HeraldBot[bot]" <149080493+heraldbot[bot]@users.noreply.github.com> Date: Fri, 20 Dec 2024 09:06:49 +0000 Subject: [PATCH 2/3] Remediate Nancy findings --- .nancy-ignore | 5 +---- 1 file changed, 1 insertion(+), 4 deletions(-) diff --git a/.nancy-ignore b/.nancy-ignore index e4c7841..56c7dea 100644 --- a/.nancy-ignore +++ b/.nancy-ignore @@ -1,4 +1 @@ -CVE-2024-0874 until=2024-11-20 # github.com/coredns/coredns@v1.10.1 -CVE-2023-28452 until=2024-11-20 # github.com/coredns/coredns@v1.10.1 -CVE-2023-30464 until=2024-11-20 # github.com/coredns/coredns@v1.10.1 -CVE-2024-51744 until=2024-12-07 # github.com/golang-jwt/jwt/v4@v4.2.0 +CVE-2024-45338 until=2025-01-19 # golang.org/x/net@v0.23.0 From 9d9cb242254f3ce440521abe50e73883f271381e Mon Sep 17 00:00:00 2001 From: "HeraldBot[bot]" <149080493+heraldbot[bot]@users.noreply.github.com> Date: Tue, 31 Dec 2024 09:06:48 +0000 Subject: [PATCH 3/3] Remediate Nancy findings --- .nancy-ignore | 1 + 1 file changed, 1 insertion(+) diff --git a/.nancy-ignore b/.nancy-ignore index 56c7dea..fa10675 100644 --- a/.nancy-ignore +++ b/.nancy-ignore @@ -1 +1,2 @@ CVE-2024-45338 until=2025-01-19 # golang.org/x/net@v0.23.0 +CVE-2024-45337 until=2025-01-30 # golang.org/x/crypto@v0.21.0