mirror of https://github.com/prometheus/prometheus
Browse Source
This PR updates go-retryablehttp to version 0.7.7, even if it's used as an indirect import. Versions previous to that can didn't sanitize urls, discussed at HDCSEC-2024-12 [1] [1] https://discuss.hashicorp.com/t/hcsec-2024-12-go-retryablehttp-can-leak-basic-auth-credentials-to-log-files/68027 Signed-off-by: Daniel Mellado <dmellado@redhat.com>pull/14351/head
Daniel Mellado
5 months ago
committed by
Ayoub Mrini
2 changed files with 6 additions and 7 deletions
Loading…
Reference in new issue