Skip to content

Multiple CVEs related to stdlib version 1.25.0 #1909

@adriansali

Description

@adriansali

What happened in your environment?

stdlib v1.25.0, that oras depends on, is affected by multiple CVEs. Here's a partial list.

Please bump the version of go to >= 1.25.2

What did you expect to happen?

No CVEs detected.

How can we reproduce it?

See links above for the details on vulnerabilities.

What is the version of your ORAS CLI?

v1.3.0

What is your OS environment?

Azure Linux 3

Are you willing to submit PRs to fix it?

  • Yes, I am willing to fix it.

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't workingtriageNew issues or PRs to be acknowledged by maintainers

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions