Uploaded image for project: 'Percona Toolkit'
  1. Percona Toolkit
  2. PT-2092

Improper version of protobuf in go.sum

Details

    • Bug
    • Status: Done
    • Medium
    • Resolution: Fixed
    • 3.4.0
    • 3.5.0
    • None
    • None
    • Yes
    • 0.5

    Description

      According to dependabot, go.sum in Percona Toolkit is vulnerable because links protobuf 1.3.1.

      Dependabot report:

      An issue was discovered in GoGo Protobuf before 1.3.2. plugin/unmarshal/unmarshal.go lacks certain index validation, aka the "skippy peanut butter" issue.

      Attachments

        Activity

          People

            Unassigned Unassigned
            sveta.smirnova Sveta Smirnova
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved:

              Smart Checklist