Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

version: Bump golang to 1.22.11 #2264

Conversation

stevenhorsman
Copy link
Member

@stevenhorsman stevenhorsman commented Jan 28, 2025

Bump golang to fix vulnerabilities:

  • GO-2025-3420
  • GO-2025-3373
  • GO-2025-3372

Following on from this will be another PR (#2265) that uses the new builder image,
but it isn't published until this is merged.

@stevenhorsman stevenhorsman requested a review from a team as a code owner January 28, 2025 09:37
Bump golang to fix vulnerabilities:
- GO-2025-3420
- GO-2025-3373
- GO-2025-3372

Following on from this will be another PR that uses the new builder image,
but it isn't published until this is merged.

Signed-off-by: stevenhorsman <steven@uk.ibm.com>
@stevenhorsman stevenhorsman force-pushed the golang-builder-image-bump-1.22.11 branch from 09183c0 to 3b42f39 Compare January 28, 2025 10:01
@stevenhorsman stevenhorsman changed the title golang-image: Update to 1.22.11 version: Bump golang to 1.22.11 Jan 28, 2025
Bump github.com/golang/glog to v1.2.4 to resolve
CVE GO-2025-3372

Signed-off-by: stevenhorsman <steven@uk.ibm.com>
Copy link
Member

@bpradipt bpradipt left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Just to re-confirm. No changes needed to cloud-provider, peerpod-ctrl and webhook ?

@stevenhorsman
Copy link
Member Author

Just to re-confirm. No changes needed to cloud-provider, peerpod-ctrl and webhook ?

None that govuln found. I think post release I might try and bump a lot of modules just to get us more up-to-date anyway.

@stevenhorsman stevenhorsman merged commit e19aaad into confidential-containers:main Jan 28, 2025
22 checks passed
@stevenhorsman stevenhorsman deleted the golang-builder-image-bump-1.22.11 branch January 28, 2025 12:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants