Skip to content

fix: bump go version to the latest patch to fix high severity CVEs#408

Merged
elenz97 merged 1 commit intomittwald:masterfrom
SebastienSyd:master
Nov 3, 2025
Merged

fix: bump go version to the latest patch to fix high severity CVEs#408
elenz97 merged 1 commit intomittwald:masterfrom
SebastienSyd:master

Conversation

@SebastienSyd
Copy link
Contributor

There are 2 high severity CVEs that can be remediated by bumping the go version to the latest patch

Here are the details:

The go command may execute unexpected commands when operating in untrusted VCS repositories. This occurs when possibly dangerous VCS configuration is present in repositories. This can happen when a repository was fetched via one VCS (e.g. Git), but contains metadata for another VCS (e.g. Mercurial). Modules which are retrieved using the go command line, i.e. via "go get", are not affected.

requires at least go 1.24.6 to be fixed

Cancelling a query (e.g. by cancelling the context passed to one of the query methods) during a call to the Scan method of the returned Rows can result in unexpected results if other queries are being made in parallel. This can result in a race condition that may overwrite the expected results with those of another query, causing the call to Scan to return either unexpected results from the other query or an error.

requires at least go 1.24.6 to be fixed

@SebastienSyd
Copy link
Contributor Author

hey @elenz97, can you please have a look at this quick PR?

thanks a lot
Sebastien

@elenz97 elenz97 self-requested a review November 3, 2025 10:42
@elenz97 elenz97 merged commit 51e012e into mittwald:master Nov 3, 2025
3 checks passed
@elenz97
Copy link
Contributor

elenz97 commented Nov 3, 2025

Thanks @SebastienSyd, the changes are now contained in the latest release 👍

@SebastienSyd
Copy link
Contributor Author

many thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants