Skip to content

Conversation

mrueg
Copy link
Contributor

@mrueg mrueg commented Dec 17, 2021

Updates vulnerable dependency (CVE-2021-44716). Not sure if this repo is affected through its net/http2 usage.

"golang.org/x/net/http2"

golang/go#50058

Edit: seems like tests are failing, probably a good time to drop support for go-1.13 and 1.14?

@LeviHarrison
Copy link
Contributor

I think the client_golang is the blocker for removing old versions (see #324 (comment)).

Updates vulnerable dependency (CVE-2021-44716). Not sure if this repo is
affected through its net/http2 usage.

Signed-off-by: Manuel Rüger <[email protected]>
@mrueg
Copy link
Contributor Author

mrueg commented Jan 7, 2022

Closing in favor of #353

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants