-
-
Notifications
You must be signed in to change notification settings - Fork 998
Open
Description
Summary
@depot/cli@0.0.1-cli.2.80.0 bundles golang.org/x/crypto@v0.19.0 which has a CRITICAL vulnerability (CVSS 9.1):
- CVE: GHSA-v778-237x-gjrc
- Issue: Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass
- Fixed in: golang.org/x/crypto >= 0.31.0
Current State
@trigger.dev/sdk@4.3.3depends ontrigger.dev@4.3.3trigger.dev@4.3.3depends on@depot/cli@0.0.1-cli.2.80.0@depot/cli@0.0.1-cli.2.101.3is available on npm (likely contains the fix)
Impact
This vulnerability is flagged by Grype and other container/binary scanners, causing security audits to fail even though the actual exploitation risk may be low for most use cases.
Request
Please update @depot/cli to the latest version (0.0.1-cli.2.101.3 or newer).
Alternatively, consider making it an optional dependency per #1597, which would allow users who don't need Depot's container building features to avoid pulling in vulnerable binaries.
References
- GitHub Advisory
- Fix Commit
- Related: feat: Make @depot/cli an optional dependency #1597 (Make @depot/cli optional)
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels