Skip to content
This repository was archived by the owner on Apr 22, 2025. It is now read-only.

Update dependencies to address CVE-2023-3635 #292

Merged
merged 1 commit into from
Nov 29, 2023

Conversation

bestbeforetoday
Copy link
Member

@bestbeforetoday bestbeforetoday commented Oct 9, 2023

This vulnerability exists in a transitive dependency used by OpenTelemetry. However, OpenTelemetry are of the opinion that they did not make use of the vulnerable capability.

@bestbeforetoday bestbeforetoday force-pushed the CVE-2023-3635 branch 2 times, most recently from 26992c8 to 4334ff5 Compare October 9, 2023 13:50
@bestbeforetoday bestbeforetoday force-pushed the CVE-2023-3635 branch 2 times, most recently from 862b0c2 to af1931e Compare November 18, 2023 09:22
@bestbeforetoday bestbeforetoday marked this pull request as ready for review November 18, 2023 13:07
@bestbeforetoday bestbeforetoday requested a review from a team November 18, 2023 13:07
@bestbeforetoday bestbeforetoday enabled auto-merge (squash) November 18, 2023 13:07
This vulnerability exists in a transitive dependency used by OpenTelemetry. However, OpenTelemetry are of the opinion that they did not make use of the vulnerable capability.

Signed-off-by: Mark S. Lewis <[email protected]>
@bestbeforetoday bestbeforetoday merged commit 35bf0aa into hyperledger:main Nov 29, 2023
@bestbeforetoday bestbeforetoday deleted the CVE-2023-3635 branch November 29, 2023 20:33
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants