Conversation
|
Some information about that problem also.
fix was https://go-review.googlesource.com/c/text/+/442235/2/language/parse.go |
|
So I am trying to understand how Echo is affected by it though these dependencies so far if you have something like in your code you are affected:
|
|
@madmuffin1 what do you think? Echo is not directly/indirectly affected because there are no code that links to that problematic function? |
|
my take on this: echo is not directly affected, but should not have a vulnerable dependency as implementing projects might refer to the affected method. our company forbids any library with vulnerable dependencies, so all our echo projects will have to explicitly bump x/text, rather than updating this dependency. |
|
as |
see https://go.dev/issue/56152, https://ossindex.sonatype.org/vulnerability/CVE-2022-32149?component-type=golang&component-name=golang.org%2Fx%2Ftext&utm_source=nancy-client&utm_medium=integration&utm_content=1.0.41