Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security Concern with Deprecated uuid package: satori/go.uuid #2132

Closed
jnaulty opened this issue Dec 14, 2019 · 0 comments · Fixed by #2133
Closed

Security Concern with Deprecated uuid package: satori/go.uuid #2132

jnaulty opened this issue Dec 14, 2019 · 0 comments · Fixed by #2133
Labels
Security Security related issues

Comments

@jnaulty
Copy link
Contributor

jnaulty commented Dec 14, 2019

Describe the problem/challenge you have
I would like to see no known security vulnerabilities reported when running vmware-tanzu/velero in the snyk.io security scan.

Describe the solution you'd like
Migrate the satori/go.uuid package which is no longer being maintained to the gofrs/uuid package.
gofrs/uuid reason for existence:

This project was originally forked from the github.com/satori/go.uuid repository after it appeared to be no longer maintained, while exhibiting critical flaws. We have decided to take over this project to ensure it receives regular maintenance for the benefit of the larger Go community.

Anything else you would like to add:
Non-Random UUID Issue in satori/go.uuid: satori/go.uuid#73
Deprecation of satori/go.uuid: satori/go.uuid#85

Snyk Report:
image

Environment:

  • Velero version (use velero version): 1.2.0
@carlisia carlisia added the Security Security related issues label Dec 14, 2019
@nrb nrb closed this as completed in #2133 Dec 16, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Security Security related issues
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants