You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
go.mod: upgrade dependencies and rid vulnerable thrift [email protected]
Coming here, after digging through
google/exposure-notifications-server#749
in which the version of github.com/apache/thrift was reported by
@whaber as having known critical vulnerabilities.
Transitively however, this version was pinning to
cloud.google.com/[email protected] indirectly, which then imported
versions of opencensus:
* [email protected].
* [email protected]
that imported
github.com/apache/[email protected]
The target package to upgrade was
github.com/denisenkom/go-mssqldb v0.0.0-20200620013148-b91950f658ec
which now uses
cloud.google.com/[email protected]
0 commit comments