Skip to content

Request for dependency updates to mitigate CVEs #300

@bencardinal

Description

@bencardinal

I am incorporating okta-aws-cli into a docker image. The GitLab container scanning (Trivy) reported two high CVEs that trace back to okta-aws-cli.

The first one, CVE-2025-22869, recommends updating to version of golang.org/x/crypto greater than 0.35.0. Currently 0.32.0 is specified in go.mod.

The second one, CVE-2025-47907, recommends updating the Go version to 1.23.12, 1.24.6. Currently 1.21 is specified in go.mod.

Updates to these would be much appreciated to help calm the security dashboards. Thanks!

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions