•  
      request #44864 Go: temporarily ignore CVE-2025-47910
    Infos
    #44864
    Joris MASSON (jmasson)
    2025-10-09 14:49
    2025-09-25 11:14
    46583
    Details
    Go: temporarily ignore CVE-2025-47910

    Security Advisory: https://pkg.go.dev/vuln/GO-2025-3955

    There is no security impact for Tuleap, because we do not use AddInsecureBypassPattern in http.CrossOriginProtection. We can temporarily ignore this and upgrade to a fixed Go version later.

    Dependencies
    Empty
    Empty
    • [ ] enhancement
    • [ ] internal improvement
    Empty
    Stage
    Joris MASSON (jmasson)
    Closed
    2025-09-25
    Attachments
    Empty
    References

    Follow-ups