Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(deps): bump Golang to v1.23 #198

Closed

Conversation

zhijie-yang
Copy link
Contributor

@zhijie-yang zhijie-yang commented Jan 27, 2025

  • Have you signed the CLA?

  • This PR bumps the Golang version to 1.23 to fix the known exploited vulnerabilities (CVE-2024-34158 and CVE-2024-34156, and CVE-2024-34155, which is a medium vulnerability not listed as a KEV) in Golang v1.21.

  • To accommodate the bumped Golang version, the golangci-lint is bumped to v1.63.4.

  • To accommodate the bumped Golang version, the Go binary is installed directly from go.dev in the spread test.

@zhijie-yang zhijie-yang marked this pull request as draft January 27, 2025 12:02
@zhijie-yang zhijie-yang changed the title chore(deps): bump go-lang to v1.23 chore(deps): bump Golang to v1.23 Jan 29, 2025
niemeyer pushed a commit that referenced this pull request Feb 4, 2025
This PR bumps the Golang version to 1.22 to fix the known exploited vulnerabilities (CVE-2024-34158 and CVE-2024-34156, and CVE-2024-34155, which is a medium vulnerability not listed as a KEV) in Golang v1.21.

To accommodate the bumped Golang version, the golangci-lint is bumped to v1.63.4.

The PR bumping Golang to v1.23 (#198) is dropped since the latest Ubuntu LTS (noble) does not officially support v1.23, which resulted in additional changes in building and testing the project.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant