pgbouncer_exporter icon indicating copy to clipboard operation
pgbouncer_exporter copied to clipboard

pgbouncer_exporter Vulnerabilities

Open kaiossoares opened this issue 5 months ago • 0 comments

Hello everyone!

The docker image "timescaledb-ha" i'm using has pgbouncer_exporter, however, I needed to scan the image using Snyk, pointing out problems in the version of the following package:

✗ High severity vulnerability found in golang.org/x/net/http2 Description: Allocation of Resources Without Limits or Throttling Info: https://security.snyk.io/vuln/SNYK-GOLANG-GOLANGORGXNETHTTP2-6531285 Introduced through: golang.org/x/net/[email protected] From: golang.org/x/net/[email protected] Fixed in: 0.23.0

Package manager: gomodules Target file: /usr/local/bin/pgbouncer_exporter Project name: github.com/prometheus-community/pgbouncer_exporter Docker image: timescaledb-ha:latest Licenses: enabled

Is it possible to have a release with the tag "0.9.0"? Probably the version of this package would be updated.

I am available and would like to contribute. Any help or advice would be appreciated.

kaiossoares avatar Aug 28 '24 19:08 kaiossoares