CVE-2022-32149 affects workhorse dependencies
golang.org/x/text v0.3.8 has been released to address CVE-2022-32149.
Workhorse is using v0.3.7 as an indirect dependency.
Whe should check what other components are affected, maybe pages, gitaly, and KAS.
https://github.com/golang/text/commit/434eadcdbc3b0256971992e8c70027278364c72c