Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update go version to > 1.20.5 #287

Open
radicand opened this issue Apr 10, 2024 · 1 comment
Open

Update go version to > 1.20.5 #287

radicand opened this issue Apr 10, 2024 · 1 comment
Labels
Build build-related changes

Comments

@radicand
Copy link

radicand commented Apr 10, 2024

Due to https://nvd.nist.gov/vuln/detail/CVE-2023-29404, https://nvd.nist.gov/vuln/detail/CVE-2023-29405, https://nvd.nist.gov/vuln/detail/CVE-2023-24540, https://nvd.nist.gov/vuln/detail/CVE-2023-24538 and several other CVE's statping is getting flagged in our security scanners. It seems go 1.20.14 is the highest released version in the 1.20 minor version branch; I am not knowledgeable enough to know if you can or want to go any higher. Nevertheless, the 1.20.0 version used in the Dockerfile build shouldn't be used.

@jemand771 jemand771 added the Build build-related changes label Apr 11, 2024
@jemand771
Copy link
Member

hey, thanks for bringing this up.

upgrading go versions can sometimes be a bit of a pain, but I'll try it and see what breaks soon™

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Build build-related changes
Projects
None yet
Development

No branches or pull requests

2 participants