Skip to content

Go Module github.com/mholt/archiver/v3 Flagged with High Security Vulnerability #424

Description

@stevesim101

Describe the bug
When trying to use the JFrog Go client, my company's enterprise SCA platform is flagging github.com/mholt/archiver/v3 with a high security vulnerability.

https://securitylab.github.com/advisories/GHSL-2020-252-zipslip-archiver

I was wondering if you could share your short-term or long-term plans to address this. Even if there is no immediate fix, I just need some insight on the current and future state of this to provide a bit of context to my company's compliance teams.

To Reproduce
N/A

Expected behavior
N/A

Screenshots
N/A

Versions

  • JFrog Go client version: v1.4.0
  • JFrog Go client operating system:
  • Artifactory version:

Additional context
Add any other context about the problem here.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

bugSomething isn't working

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions