-
-
Notifications
You must be signed in to change notification settings - Fork 998
Open
Description
Summary
@depot/[email protected] bundles golang.org/x/[email protected] which has a CRITICAL vulnerability (CVSS 9.1):
- CVE: GHSA-v778-237x-gjrc
- Issue: Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass
- Fixed in: golang.org/x/crypto >= 0.31.0
Current State
@trigger.dev/[email protected]depends on[email protected][email protected]depends on@depot/[email protected]@depot/[email protected]is available on npm (likely contains the fix)
Impact
This vulnerability is flagged by Grype and other container/binary scanners, causing security audits to fail even though the actual exploitation risk may be low for most use cases.
Request
Please update @depot/cli to the latest version (0.0.1-cli.2.101.3 or newer).
Alternatively, consider making it an optional dependency per #1597, which would allow users who don't need Depot's container building features to avoid pulling in vulnerable binaries.
References
- GitHub Advisory
- Fix Commit
- Related: feat: Make @depot/cli an optional dependency #1597 (Make @depot/cli optional)
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels