The version of golang.org/x/crypto used in Burrow's Release v1.9.5 is 0.42. Please release an updated version to address the vulnerability
Open
- Dominant language
- Go
- Stars
- 4k
- Forks
- 818
- Avg merge
- 1h 14m
- Merged PRs (30d)
- 1
Description
[CVE-2025-47913]
Contributor guide
No contributing guide indexed for this repository
Research direction
Start by reviewing the dependency metadata for Release v1.9.5 and the project's release process, then verify which golang.org/x/crypto version addresses CVE-2025-47913. Done means an updated Burrow release is available with the vulnerable dependency replaced.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- go
- Domain
- security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100