Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

request: vulnerability fix #36

Closed
mvforster opened this issue Jun 20, 2024 · 6 comments
Closed

request: vulnerability fix #36

mvforster opened this issue Jun 20, 2024 · 6 comments

Comments

@mvforster
Copy link

Following the inclusion of your plugin within a NextFlow (24.04.2) container that I am building, a scan of the container detected an issue with the org.json/json 20230227 package.

The associated CVES is lined here which is a duplicate of this issue and has been reported to be fixed by this Pull Request

The vulnerability was reported by Docker Scout v1.8.0.

Would it be possible to patch this vulnerability in nf-schema? I am keen to use nf-schema as part of my workflow but will not be able to do so until the vulnerability has been patched.

Many thanks for your assistance with this.

@nvnieuwk
Copy link
Collaborator

nvnieuwk commented Jul 3, 2024

Hi thank you for reporting this! I'll have a look how much work this would be

@nvnieuwk
Copy link
Collaborator

nvnieuwk commented Jul 3, 2024

(Sorry for the long wait, it seems like the notification for your issue got lost in between all other notifications 😁)

@mvforster
Copy link
Author

Thanks for the prompt action, @nvnieuwk :) I get that notifications can get lost. I can see that the patch is well underway.

I hope it doesn't break anything.

@nvnieuwk
Copy link
Collaborator

nvnieuwk commented Jul 3, 2024

It's looking fine at the moment. All tests seem to pass :). People can still revert back to v2.0.0 if it causes issues

@nvnieuwk
Copy link
Collaborator

nvnieuwk commented Jul 5, 2024

The fix has been implemented in version 2.0.1 🥳

@nvnieuwk nvnieuwk closed this as completed Jul 5, 2024
@mvforster
Copy link
Author

Thanks for the prompt action 🎊

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants