Skip to content

Conversation

@0x4c6565
Copy link

@0x4c6565 0x4c6565 commented May 3, 2023

Fixes #381

@CLAassistant
Copy link

CLAassistant commented May 3, 2023

CLA assistant check
All committers have signed the CLA.

@MShekow
Copy link

MShekow commented Sep 23, 2023

@bep could this be merged? Because of the insecure xtext dependency, any Go-based software using aferofs is flagged as insecure by scanners.

@bmwaechter
Copy link

bump on this, is there a reason this can't be merged? its causing a tons of CVE vulns for a lot of people, seems low risk to fix.

@sagikazarmark
Copy link
Collaborator

Updated dependencies in #439

Since that function is exported, removing it would be a breaking change, so I would leave that in for now. The text package is a transitive dependency anyway.

Thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

CVE-2022-32149: golang.org/x/text < 0.3.8

5 participants