Security context

What an agent needs to avoid regressing past fixes and find the next vuln in this repo.

pact-foundation/pact-go
master @ f94bb35
15
Fixes
0
CVEs
HIGH
Peak severity
100.0%
Coverage
Highlights
Dependency Vulnerability: 15 prior fixes. Scrutinize any change in this area.
Dockerfile: most-fixed (14 issues). Treat as high-risk during review.
1 high-severity fix in this history; regressions here are high-impact.
Recurring patterns

The bug types that recur here, drawn from past fixes, not open vulnerabilities.

Dependency Vulnerability: The base image has been the source of numerous high and medium severity vulnerabilities across system libraries, requiring frequent major version jumps (e.g., 1.10.1 to 1.19.10).
Dependency Vulnerability: Recurring medium-severity vulnerabilities in glibc, zlib, and other libraries have forced incremental base image upgrades across multiple Go versions, indicating a persistent need for vigilance.
Dependency Vulnerability: Upgrades from older base images (1.15, 1.16, 1.17) to newer ones were needed to address vulnerabilities in OpenSSL, Python, Git, and other utilities, showing that even 'recent' images can carry risk.