Head of Product & Engineering c98ba0d4d6
All checks were successful
ci/woodpecker/push/woodpecker Pipeline was successful
fix: upgrade golang.org/x/crypto to v0.35.0 (CVE-2025-22869)
Trivy flagged golang.org/x/crypto v0.33.0 with HIGH severity
CVE-2025-22869 (DoS in SSH key exchange). Upgraded to v0.35.0
which contains the fix.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-04-05 23:20:05 +02:00

20 lines
530 B
Modula-2

module git.sds.dev/CAST/cast-ghl-plugin
go 1.26.1
require (
github.com/go-chi/chi/v5 v5.2.5
go.mongodb.org/mongo-driver/v2 v2.5.0
)
require (
github.com/klauspost/compress v1.17.6 // indirect
github.com/xdg-go/pbkdf2 v1.0.0 // indirect
github.com/xdg-go/scram v1.2.0 // indirect
github.com/xdg-go/stringprep v1.0.4 // indirect
github.com/youmark/pkcs8 v0.0.0-20240726163527-a2c0da244d78 // indirect
golang.org/x/crypto v0.35.0 // indirect
golang.org/x/sync v0.11.0 // indirect
golang.org/x/text v0.22.0 // indirect
)