Resolves: CVE-2022-41723 Ref: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2022-41723 bumped golang to 1.17 Signed-off-by: Lokesh Mandvekar <lsm5@fedoraproject.org>
... to include a fix for https://github.com/advisories/GHSA-c2h3-6mxw-7mvq . (Note that Skopeo doesn't depend on the vulnerable code, so this is primarily to avoid dependency checker warnings.) Signed-off-by: Miloslav Trmač <mitr@redhat.com>
Based on https://github.com/projectatomic/skopeo/pull/289 by Erik Hollensbe <github@hollensbe.org> Signed-off-by: Miloslav Trmač <mitr@redhat.com>