open-policy-agent/frameworks

Upgrade OPA to v0.40.0

willbeason opened this issue · 4 comments

There's a CVE for OPA v0.39.0 which can cause a DOS: https://ossindex.sonatype.org/vulnerability/CVE-2022-28946

See open-policy-agent/opa#4548 for motivation

Should dependabot have detected this and bumped the version?

That's a good point! It should have

@sozercan I don't think dependabot has been running since it was added. Could it be that we are looking at / instead of /constraint?

@ritazh good catch! opened #229