Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Snyk is reporting CVE-2023-7104 #2693

Open
monwolf opened this issue May 14, 2024 · 2 comments
Open

Snyk is reporting CVE-2023-7104 #2693

monwolf opened this issue May 14, 2024 · 2 comments
Assignees
Labels
bug unintended behavior that has to be fixed

Comments

@monwolf
Copy link

monwolf commented May 14, 2024

Good afternoon,
We are using snyk to detect 3rd party vulns in our projects and we are getting a high vulnerability from your package.

gopkg.in/DataDog/dd-trace-go.v1@v1.63.1

image

To fix it, you just have to update from go-sqlite3@v1.14.16 to go-sqlite3@1.14.18 1.14.18

Best Regards,

@monwolf monwolf added the bug unintended behavior that has to be fixed label May 14, 2024
@github-actions github-actions bot added the needs-triage New issues that have not yet been triaged label May 14, 2024
@darccio darccio self-assigned this May 14, 2024
@darccio darccio removed the needs-triage New issues that have not yet been triaged label May 14, 2024
@monwolf
Copy link
Author

monwolf commented May 23, 2024

Hi @darccio,

have you had time to review this issue?

Regards,

@darccio
Copy link
Contributor

darccio commented May 23, 2024

@monwolf Yes, sorry, my reply slipped through the cracks. You can fix it in your side by importing v1.14.18 while we merge the update and release the next version.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug unintended behavior that has to be fixed
Projects
None yet
Development

No branches or pull requests

2 participants