kubo-fips
Chainguard
5.3
CVSS V3
Status
Impact
quic-go 0.56.0 removed the logging and metrics packages which kubo depends upon, meaning builds against the fixed version (0.57.1) fail. To remediate this vulnerability, kubo upstream will need to adapt their code to the new quic-go API and cut a release.
Status
Justification
Impact
Govulncheck found no affected symbols in the scanned Go binaries.
Status