appleboy / appleboy/lambda-action
Vulnerabilities in golang/crypto < 0.35.0 and golang/net < 0.38.0
- Dominant language
- D2
- Stars
- 435
- Forks
- 57
- PR merge metrics
- No merged PRs in 30d
Description
Two of the golang packages used in this action contains vulnerabilities. Would really appreciate if these could be patched soon 🙏
```yml
uses: appleboy/lambda-action@v0.2.0
```
Critical severity vulnerabilities .. 🔥
| Vulnerability | Package |
-- | --
| [GHSA-v778-237x-gjrc](https://github.com/advisories/GHSA-v778-237x-gjrc) | pkg:golang/golang.org/x/crypto@v0.22.0 |
High severity vulnerabilities .. ⚠️
| Vulnerability | Package |
-- | --
| [GHSA-hcg3-q754-cr77](https://github.com/advisories/GHSA-hcg3-q754-cr77) | pkg:golang/golang.org/x/crypto@v0.22.0 |
Medium severity vulnerabilities ..
| Vulnerability | Package |
-- | --
| [GHSA-qxp5-gwg8-xv66](https://github.com/advisories/GHSA-qxp5-gwg8-xv66) | pkg:golang/golang.org/x/net@v0.24.0 |
| [GHSA-vvgc-356p-c3xw](https://github.com/advisories/GHSA-vvgc-356p-c3xw) | pkg:golang/golang.org/x/net@v0.24.0
Contributor guide
No contributing guide indexed for this repository
Assessment
This issue has not been assessed yet.