Skip to content

[🐸 Frogbot] Update version of github.com/theupdateframework/go-tuf/v2 to 2.3.1#30

Merged
dortam888 merged 2 commits intomainfrom
frogbot-github.com/theupdateframework/go-tuf/v2-0f8aea49a324f9b5c12ae8a52fe31e35
Jan 25, 2026
Merged

[🐸 Frogbot] Update version of github.com/theupdateframework/go-tuf/v2 to 2.3.1#30
dortam888 merged 2 commits intomainfrom
frogbot-github.com/theupdateframework/go-tuf/v2-0f8aea49a324f9b5c12ae8a52fe31e35

Conversation

@github-actions
Copy link
Contributor

🚨 This automated pull request was created by Frogbot and fixes the below:

📦 Vulnerable Dependencies

Severity ID Contextual Analysis Direct Dependencies Impacted Dependency Fixed Versions
medium
Medium
CVE-2026-23992 Not Covered github.com/theupdateframework/go-tuf/v2:v2.3.0 github.com/theupdateframework/go-tuf/v2 v2.3.0 [2.3.1]

🔖 Details

Vulnerability Details

Contextual Analysis: Not Covered
Direct Dependencies: github.com/theupdateframework/go-tuf/v2:v2.3.0
Impacted Dependency: github.com/theupdateframework/go-tuf/v2:v2.3.0
Fixed Versions: [2.3.1]
CVSS V3: 5.9

go-tuf improperly validates the configured threshold for delegations


@dortam888 dortam888 added the security Security-related fixes or improvements label Jan 25, 2026
@dortam888 dortam888 merged commit 1c6f4f3 into main Jan 25, 2026
16 of 18 checks passed
@dortam888 dortam888 deleted the frogbot-github.com/theupdateframework/go-tuf/v2-0f8aea49a324f9b5c12ae8a52fe31e35 branch January 25, 2026 12:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

security Security-related fixes or improvements

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants