Skip to content

Conversation

@dfangl
Copy link
Member

@dfangldfangl commented Dec 12, 2024

Motivation

golang.org/x/net v0.18.0 has a moderate CVE reported which some customer tooling reports as high: https://avd.aquasec.com/nvd/2023/cve-2023-45288/ , GHSA-4v7x-pqxf-cx7m

Updating the xray daemon dependency also upgrades golang.org/x/net.

Related to localstack/localstack#12011

Changes

  • Upgrade github.com/aws/aws-xray-daemon and its dependencies
  • No behavioral changes expected

@dfangldfangl requested a review from joe4devDecember 12, 2024 14:55
@dfangldfangl merged commit 0b2b5be into localstackDec 17, 2024
1 check passed
@dfangldfangl deleted the upgrade-dependencies branch December 17, 2024 15:58
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@dfangl@joe4dev