Skip to content

Conversation

@avijoenil
Copy link

@avijoenil avijoenil commented Sep 14, 2023

Because of the vulnerabilites found in the following scan. The ghinstallation dependency is bumped to 2.7.0

@pedrohdz
Copy link

To be specific, this addressed the CVE-2022-39304 and CVE-2020-26160 security vulnerabilities.

For those that find this PR. Note that I went ahead and forked this repo and merged this fix and others at Avinode/git-credential-github-apps. We started using this Git credentials provider and needed these security related patches applied in order to continue utilizing it. We have also published a v1.2.0 release there.

I don't want to step on anyone's toes, and will gladly close down the fork if this repo comes back to life.

Thanks for this fix! We needed it!

@mackee
Copy link
Owner

mackee commented Jan 18, 2025

@avijoenil @pedrohdz Thank you for your Pull Request. I apologize for leaving it unattended for so long. I will review the current situation and create a new Pull Request to incorporate these fixes.

@mackee mackee closed this Jan 18, 2025
@mackee mackee mentioned this pull request Jan 18, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants