Skip to content

deps: bump viper to fix mapstructure vulnerabilities#391

Open
gojuukaze wants to merge 2 commits intosolana-foundation:mainfrom
gojuukaze:upgrade_viper
Open

deps: bump viper to fix mapstructure vulnerabilities#391
gojuukaze wants to merge 2 commits intosolana-foundation:mainfrom
gojuukaze:upgrade_viper

Conversation

@gojuukaze
Copy link
Copy Markdown

viper depends on mapstructure/v2, which has multiple known security vulnerabilities reported by security scanners.

While these issues may not be directly exploitable in all use cases, they can still introduce potential risks and trigger alerts in downstream environments.

Upgrading viper ensures a newer version of mapstructure/v2 is used, mitigating these vulnerabilities.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant