Package
watchexec
Component
gix-date
Latest update
Fixed version
2.3.3-r0
7.1
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Fixed version
2.3.3-r0Status
Impact
This vulnerability affects gix-date 0.10.2, a transitive dependency of watchexec v2.3.2. The vulnerability is fixed in gix-date >= 0.12.0, but upgrading is blocked by version incompatibilities in the dependency chain.
Dependency Chain:
The gix v0.72.1 constraint (^0.10.1) prevents upgrading gix-date to 0.12.0. Upgrading gix-date requires gix 0.77.0+, which in turn requires a new watchexec release.
In order to remediate this vulnerability, upstream must release a new version of watchexec that uses gix 0.77.0 or later, which supports gix-date 0.12.0+.
Status