-
-
Notifications
You must be signed in to change notification settings - Fork 47
Open
Description
@jinzhu Hi there,
I’m using go-gorm/sqlserver, which depends on go-mssqldb v1.8.2. That go-mssqldb version has some known security issues:
CVE-2024-35255 (github.com/Azure/azure-sdk-for-go/sdk/azidentity v1.3.1)
CVE-2025-30204 (github.com/golang-jwt/jwt/v5 v5.0.0 / v5.2.1)
Since go-mssqldb v1.9.1+ has already fixed these, I was wondering if there are any plans to update go-gorm/sqlserver to use the newer version.
Thanks!
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels