Join Slack
Powered by
<#3366 [Housekeeping] Replace satori/go.uuid in da...
# flyte-github
a
acoustic-carpenter-78188
02/23/2023, 2:22 PM
#3366 [Housekeeping] Replace satori/go.uuid in datacatalog
Issue created by
hajapy
Describe the issue
Replace "
github.com/satori/go.uuid
" in
datacatalog
with a maintained library (possibly
https://github.com/gofrs/uuid
or
https://github.com/google/uuid
).
What if we do not do this?
github.com/satori/go.uuid
is vulnerable to
https://nvd.nist.gov/vuln/detail/CVE-2021-3538
, which is listed as a CRITICAL, which makes datacalog potentially vulnerable as well. Continuing to use an unmaintained library is also not ideal should additional vulnerabilities or issues come up in this library.
Related component(s)
datacatalog, flyte single binary
Are you sure this issue hasn't been raised already?
☑︎ Yes
Have you read the Code of Conduct?
☑︎ Yes
flyteorg/flyte
acoustic-carpenter-78188
03/20/2023, 5:21 PM
#3366 [Housekeeping] Replace satori/go.uuid in datacatalog
Issue closed as completed by
hamersaw
flyteorg/flyte
Open in Slack
Previous
Next