Skip to content

move to building with Go 1.23.6 and updated golang.org/x/ deps#744

Merged
tvoran merged 5 commits intomainfrom
bump_go_deps
Feb 24, 2025
Merged

move to building with Go 1.23.6 and updated golang.org/x/ deps#744
tvoran merged 5 commits intomainfrom
bump_go_deps

Conversation

@finnigja
Copy link
Contributor

Move to building with newest Go 1.23 release.

The move from 1.23.4 and update of several golang.org/x dependencies addresses several CVEs which show up on vulnerability scanners (CVE-2024-45336, CVE-2024-45341, CVE-2025-22866, CVE-2024-45338) but are unlikely to be exposed in vault-k8s context.

@finnigja finnigja requested a review from a team as a code owner February 24, 2025 17:45
Copy link
Member

@tvoran tvoran left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks!

@tvoran tvoran merged commit a4adc07 into main Feb 24, 2025
21 checks passed
@tvoran tvoran deleted the bump_go_deps branch February 24, 2025 18:23
@tvoran tvoran added this to the 1.6.2 milestone Feb 26, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants