Skip to content

Security: Request new release to fix critical CVEs in odo 3.16.1 dependencies #7314

@p13rr0m

Description

@p13rr0m

Hello,

Our ACS scan reports critical CVEs in odo v3.16.1:

  • CVE-2024-41110github.com/docker/docker v20.10.24, fixed in 23.0.15
  • CVE-2025-21613 / 21614github.com/go-git/go-git/v5 v5.11.0, fixed in 5.13.0

Binary source:
https://developers.redhat.com/content-gateway/rest/mirror/pub/openshift-v4/clients/odo/v3.16.1/odo-linux-amd64

Could you please update these dependencies and publish a new odo release that includes the security fixes?

Thanks!

Metadata

Metadata

Assignees

No one assigned

    Labels

    needs-triageIndicates an issue or PR lacks a `triage/*` and requires one.

    Type

    No type

    Projects

    Status

    No status

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions