Skip to content
Permalink

Comparing changes

Choose two branches to see what’s changed or to start a new pull request. If you need to, you can also or learn more about diff comparisons.

Open a pull request

Create a new pull request by comparing changes across two branches. If you need to, you can also . Learn more about diff comparisons here.
base repository: amacneil/dbmate
Failed to load repositories. Confirm that selected base ref is valid, then try again.
Loading
base: v2.24.0
Choose a base ref
...
head repository: amacneil/dbmate
Failed to load repositories. Confirm that selected head ref is valid, then try again.
Loading
compare: v2.24.1
Choose a head ref
  • 2 commits
  • 3 files changed
  • 2 contributors

Commits on Dec 19, 2024

  1. Upgrade golang.org/x/crypto to v0.31.0 (#603)

    Description:
    This PR updates golang.org/x/crypto to the latest version (v0.31.0) to
    mitigate the security vulnerability identified as
    [CVE-2024-45337](https://nvd.nist.gov/vuln/detail/CVE-2024-45337).
    
    Summary of Changes:
    Updated go.mod to require golang.org/x/crypto@v0.31.0.
    Ran go mod tidy to clean up dependencies.
    Why This Change Is Important:
    The previously used version of golang.org/x/crypto was affected by
    CVE-2024-45337. Upgrading to v0.31.0 resolves this issue and ensures the
    library remains secure and up-to-date.
    
    Impact:
    No breaking changes are expected as v0.31.0 is backward-compatible with
    prior versions.
    Improves the security posture of the project by addressing a critical
    vulnerability.
    
    References:
    CVE-2024-45337: https://nvd.nist.gov/vuln/detail/CVE-2024-45337
    Golang changelog for x/crypto: https://pkg.go.dev/golang.org/x/crypto
    Please let me know if you have any feedback or require additional
    changes. Thank you for reviewing this PR!
    TMathers-rula authored Dec 19, 2024
    Configuration menu
    Copy the full SHA
    0abc77b View commit details
    Browse the repository at this point in the history
  2. v2.24.1 (#604)

    Patch release to fix CVE in `golang.org/x/crypto` 
    
    - #603
    amacneil authored Dec 19, 2024
    Configuration menu
    Copy the full SHA
    f89e97f View commit details
    Browse the repository at this point in the history
Loading