Upgrade OPA to v0.40.0
willbeason opened this issue · 4 comments
willbeason commented
There's a CVE for OPA v0.39.0 which can cause a DOS: https://ossindex.sonatype.org/vulnerability/CVE-2022-28946
See open-policy-agent/opa#4548 for motivation
ritazh commented
Should dependabot have detected this and bumped the version?
willbeason commented
That's a good point! It should have