-
Notifications
You must be signed in to change notification settings - Fork 118
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Suspected vulnerabilities in dependencies #279
Comments
Hi 👋 You could switch to the 2.8.0 pre-release, which bumps the versions of the dependencies. |
Hi! Kindly tell me if it is stable enough to use. Thanks for fast response! |
Yes, the pre-release can be used. It adds support for the OpenPGP crypto-refresh if enabled, which is not fully published yet. This is why it is still a pre-release.
GopenPGP does not rely on the SSH features in x/crypto, so it is fine: |
So it's not used, just indirect dependency of another dependency which is not used in your project? |
dependabot complains that some of your library dependencies have known vulnerabilities. This is about github.com/cloudflare/circl and golang.org/x/crypto
Proposes from bot:
..exactly the same as from Goland IDE. Is it possible to upgrade to versions that are considered secure?
The text was updated successfully, but these errors were encountered: