geoipupdate
geoipupdate copied to clipboard
High vulnerabilities detected within the latest version
The latest package/release 7.1.1 seems to leverage stdlib v1.24.5 which contains vulnerability that are flagged by my CI. That would be great if a repackage could be done just to update / patch those.
Neither of those CVEs appear to affect geoipupdate. We don't use LookPath nor database/sql.
Neither of those CVEs appear to affect
geoipupdate. We don't useLookPathnordatabase/sql.
That's totally true, but it creates false positives due to "stdlib" having a vulnerable version.