Skip to content

fix(vuln): update gogetter to version 1.8.1#7743

Merged
cx-rui-araujo merged 1 commit into
masterfrom
update-gogetter-fix-vulnerability
Sep 29, 2025
Merged

fix(vuln): update gogetter to version 1.8.1#7743
cx-rui-araujo merged 1 commit into
masterfrom
update-gogetter-fix-vulnerability

Conversation

@cx-artur-ribeiro

@cx-artur-ribeiro cx-artur-ribeiro commented Sep 29, 2025

Copy link
Copy Markdown
Contributor

Reason for Proposed Changes

  • go-getter library subdirectory download feature is vulnerable to symlink attacks leading to unauthorized read access beyond the designated directory boundaries. This vulnerability, identified as CVE-2025-8959, is fixed in go-getter 1.7.9.

Proposed Changes

  • Update go-getter to version 1.8.1 (latest version);

I submit this contribution under the Apache-2.0 license.

@cx-artur-ribeiro cx-artur-ribeiro self-assigned this Sep 29, 2025
@cx-artur-ribeiro cx-artur-ribeiro requested a review from a team as a code owner September 29, 2025 11:16
@github-actions

Copy link
Copy Markdown
Contributor

kics-logo

KICS version: v2.1.13

Category Results
CRITICAL CRITICAL 0
HIGH HIGH 0
MEDIUM MEDIUM 0
LOW LOW 0
INFO INFO 0
TRACE TRACE 0
TOTAL TOTAL 0
Metric Values
Files scanned placeholder 1
Files parsed placeholder 1
Files failed to scan placeholder 0
Total executed queries placeholder 47
Queries failed to execute placeholder 0
Execution time placeholder 0

@cx-rui-araujo cx-rui-araujo merged commit 5e55e7b into master Sep 29, 2025
29 of 31 checks passed
@cx-rui-araujo cx-rui-araujo deleted the update-gogetter-fix-vulnerability branch September 29, 2025 12:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants