Skip to content

Conversation

rgmz
Copy link
Contributor

@rgmz rgmz commented Feb 24, 2025

Description:

The primary motivation for this PR is to eliminate old versions of golang.org/x/text from the dependency chain. It has several critical/high CVEs which can cause Gitleaks to be flagged in regulated environments.

Checklist:

  • Does your PR pass tests?
  • Have you written new tests for your changes?
  • Have you lint your code locally prior to submission?

This eliminates golang.org/x/text@v0.3.0 from the dependency chain, which is associated with a critical CVE that can cause Gitleaks to be flagged in regulated environments.
@rgmz rgmz force-pushed the build/upgrade-deps branch from 764802f to 1072454 Compare February 24, 2025 14:45
@zricethezav zricethezav merged commit 3fdc9c1 into gitleaks:master Feb 24, 2025
2 checks passed
@rgmz rgmz deleted the build/upgrade-deps branch February 24, 2025 14:51
sirakav pushed a commit to sirakav/gitleaks that referenced this pull request Apr 25, 2025
This eliminates golang.org/x/text@v0.3.0 from the dependency chain, which is associated with a critical CVE that can cause Gitleaks to be flagged in regulated environments.
alayne222 pushed a commit to alayne222/gitleaks that referenced this pull request May 28, 2025
This eliminates golang.org/x/text@v0.3.0 from the dependency chain, which is associated with a critical CVE that can cause Gitleaks to be flagged in regulated environments.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants