diff --git a/CHANGELOG.md b/CHANGELOG.md index 5ad1483978f..4d6f6a88d2a 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,5 +1,11 @@ # Changelog +## 2.13.1 + +### Grafana Mimir + +* [BUGFIX] Upgrade Go to 1.22.9 to address [CVE-2024-34156](https://nvd.nist.gov/vuln/detail/CVE-2024-34156). #10097 + ## 2.13.0 ### Grafana Mimir diff --git a/Makefile b/Makefile index 8ddd4984bc0..495fbddad07 100644 --- a/Makefile +++ b/Makefile @@ -275,7 +275,7 @@ mimir-build-image/$(UPTODATE): mimir-build-image/* # All the boiler plate for building golang follows: SUDO := $(shell docker info >/dev/null 2>&1 || echo "sudo -E") BUILD_IN_CONTAINER ?= true -LATEST_BUILD_IMAGE_TAG ?= pr8604-40bd216be4 +LATEST_BUILD_IMAGE_TAG ?= pr10097-2f1432e4d6 # TTY is parameterized to allow Google Cloud Builder to run builds, # as it currently disallows TTY devices. This value needs to be overridden diff --git a/mimir-build-image/Dockerfile b/mimir-build-image/Dockerfile index a26db0f6dab..577497b9c2c 100644 --- a/mimir-build-image/Dockerfile +++ b/mimir-build-image/Dockerfile @@ -5,7 +5,7 @@ FROM registry.k8s.io/kustomize/kustomize:v5.4.1 as kustomize FROM alpine/helm:3.14.4 as helm -FROM golang:1.22.5-bookworm +FROM golang:1.22.9-bookworm ARG goproxyValue ENV GOPROXY=${goproxyValue} ENV SKOPEO_DEPS="libgpgme-dev libassuan-dev libbtrfs-dev libdevmapper-dev pkg-config"