-
Bug
-
Resolution: Won't Do
-
Normal
-
None
-
4.16.z
-
None
-
Quality / Stability / Reliability
-
False
-
-
None
-
Low
-
None
-
None
-
None
-
None
-
None
-
None
-
None
-
None
-
None
-
None
-
None
-
None
Description of problem:
Hello, this is a request to fix the `go-git/go-git` dependency in the oc binary. The scanner reports the CVE [1] and [2] due to the dependency. The fixed version should be 5.13.0 or newer. [3][4] [1] - https://access.redhat.com/security/cve/cve-2025-21614 [2] - https://access.redhat.com/security/cve/cve-2025-21613 [3] - https://github.com/go-git/go-git/security/advisories/GHSA-r9px-m959-cxf4 [4] - https://github.com/go-git/go-git/security/advisories/GHSA-v725-9546-7q7m
Version-Release number of selected component (if applicable):
OpenShift Container Platform 4.16