Skip to content

Vulnerability fix & Docker Option#2

Open
jkamenik wants to merge 5 commits into
step-security:mainfrom
Gomboc-AI:main
Open

Vulnerability fix & Docker Option#2
jkamenik wants to merge 5 commits into
step-security:mainfrom
Gomboc-AI:main

Conversation

@jkamenik

Copy link
Copy Markdown

I found and used your tool to help in judging the blast radius of the Trivy issue. Thank you for doing the leg work.

To get it to work for us I had to patch a high vulnerability and add Docker for building without the need of Go locally.

I offer our changes back to you.

dependabot Bot and others added 5 commits March 23, 2026 21:45
Bumps [golang.org/x/oauth2](https://github.com/golang/oauth2) from 0.21.0 to 0.27.0.
- [Commits](golang/oauth2@v0.21.0...v0.27.0)

---
updated-dependencies:
- dependency-name: golang.org/x/oauth2
  dependency-version: 0.27.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
…/x/oauth2-0.27.0

Bump golang.org/x/oauth2 from 0.21.0 to 0.27.0
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant