•  
      request #41789 github.com/hashicorp/yamux: ignore GO-2025-3408
    Infos
    #41789
    Thomas Gerbet (tgerbet)
    2025-01-31 15:41
    2025-01-29 11:53
    43465
    Details
    github.com/hashicorp/yamux: ignore GO-2025-3408

    No impact in our situation. The vault-tuleap-plugin is not really supposed to accept untrusted connections.

    https://pkg.go.dev/vuln/GO-2025-3408

    Other
    Empty
    Empty
    • [ ] enhancement
    • [ ] internal improvement
    Empty
    Stage
    Thomas Gerbet (tgerbet)
    Closed
    2025-01-29
    Attachments
    Empty
    References

    Follow-ups

    User avatar
    Thomas Gerbet (tgerbet)2025-01-29 11:55
    • Summary
      -github.com/hashicorp/yamux: 0.1.1 -> 0.1.2 
      +github.com/hashicorp/yamux: ignore GO-2025-3408 
    • Original Submission
      Something went wrong, the follow up content couldn't be loaded
      Only formatting have been changed, you should switch to markup to see the changes