-
Notifications
You must be signed in to change notification settings - Fork 18k
x/tools/cmd/godoc: jquery can be updated to a newer version #39535
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Comments
/cc @dmitshur |
Thanks for the report. The It can still be updated to a newer version. |
Any intention on upgrading jquery to a later version? Seeing this issue pop up in a scan. |
Looks like there's a fix for this awaiting review: golang/tools#250 |
(CC @golang/security) |
For people facing similar issues
I'm new to Go, its literally my second week, so there could be a better solution out there |
@jakinniranye thanks for sharing, unfortunately your fix requires to pull the dependency from a forked repo, not from the original repo, and this is not acceptable in some environments. |
Yes, you are correct. It's just a temporary fix. The original repo should be forked into the organisation and made read-only, they might help with approval. |
We have established that golang.org/x/tools is not affected by the reported vulnerabilities, see #39535 (comment). If your scanner erroneously reports these false positives and provides no way to override the incorrect flag, that's a shortcoming in your scanner that should be addressed by the scanner vendor. |
@FiloSottile thanks for your help! the issue tho is that If golang.org/x/tools is not affected by this vulnerability then it would help if this issue was "officially" closed with a comment: this way we could request to mark this issue as false positive on our scanners. As of now, the issue is still open, hence an override request would hardly be accepted. |
cmd/godoc is deprecated. |
The version of jquery in godoc is susceptible to a security vulnerability.
The text was updated successfully, but these errors were encountered: