lifecycle icon indicating copy to clipboard operation
lifecycle copied to clipboard

CVE(s) found in v0.19.0

Open github-actions[bot] opened this issue 1 year ago • 0 comments

Latest lifecycle release v0.19.0 triggered CVE(s) from Grype. For further details, see: https://github.com/buildpacks/lifecycle/actions/runs/8320238462 json: { "id": "GHSA-8r3f-844c-mc37", "severity": "Medium", "description": "Golang protojson.Unmarshal function infinite loop when unmarshaling certain forms of invalid JSON" }

github-actions[bot] avatar Mar 18 '24 02:03 github-actions[bot]