sentry-go icon indicating copy to clipboard operation
sentry-go copied to clipboard

Security vulnerabilities report

Open TheoBrigitte opened this issue 2 years ago • 0 comments

Summary

On latest master , nancy found 4 vulnerable dependencies with 5 high to critical CVEs.

Steps To Reproduce

$ git checkout master
$ CGO_ENABLED=0 go list -json -m all | nancy sleuth --skip-update-check --quiet -x /dev/null
...

5 Vulnerable Packages

┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓
┃ Summary                       ┃
┣━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━┫
┃ Audited Dependencies    ┃ 129 ┃
┣━━━━━━━━━━━━━━━━━━━━━━━━━╋━━━━━┫
┃ Vulnerable Dependencies ┃ 5   ┃
┗━━━━━━━━━━━━━━━━━━━━━━━━━┻━━━━━┛

Expected Behavior

Zero security vulnerability found.

$ CGO_ENABLED=0 go list -json -m all | nancy sleuth --skip-update-check --quiet -x /dev/null
┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓
┃ Summary                       ┃
┣━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━┫
┃ Audited Dependencies    ┃ 136 ┃
┣━━━━━━━━━━━━━━━━━━━━━━━━━╋━━━━━┫
┃ Vulnerable Dependencies ┃ 0   ┃
┗━━━━━━━━━━━━━━━━━━━━━━━━━┻━━━━━┛

Environment

- Go version: 1.19
- Nancy version: 1.0.37-1
- sentry-go version: 26ea60338007cb88445870a06353fb79df9d8338

Additional context

This was already reported in multiple issues: #423 #438 #445

TheoBrigitte avatar Aug 08 '22 16:08 TheoBrigitte