Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vulnerable dependency found - remove_dir_all #1695

Open
matt-intercom opened this issue Apr 13, 2023 · 1 comment
Open

Vulnerable dependency found - remove_dir_all #1695

matt-intercom opened this issue Apr 13, 2023 · 1 comment

Comments

@matt-intercom
Copy link

Our oso fork was flagged with unpatched vulnerable dependency remove_dir_all. Github advisory: GHSA-mc8h-8q98-g5hr

It seems Oso currently uses version 0.5.3, while the patched version is 0.8.0+.

It's not clear to me if the vulnerability is reachable/exploitable.

Please update the vulnerable library version or explain why the update is not needed (e.g. if this is not reachable/unexploitable in the way how Oso uses the dependency).

@samscott89
Copy link
Member

Hey @matt-intercom

It looks like that's pulled in as a transitive dependency of tempfile -- which is a package we use in development only for creating temporary files in tests, and of cbindingen -- which is a compile-time only dependency that generates C header files for us. Neither of these dependencies are included in any distributed components.

However, we'll still look to upgrade this dependency when possible.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants