Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore: Bump Go version to 1.17.8 #8222

Closed
wants to merge 1 commit into from

Conversation

terrytangyuan
Copy link
Member

Upgrading Go to 1.17.8 would resolve the following CVEs:

GHSA-8c83-vp4v-h7fq | critical | | go | 1.17.6 | fixed in 1.17.7, 1.16.14 | 11-Feb-2022 00:00 | 21-Mar-2022 13:11
GHSA-6685-ffxp-xm6f | high | | go | 1.17.6 | fixed in 1.17.8, 1.16.15 | 03-Mar-2022 00:00 | 21-Mar-2022 13:11
GHSA-52j8-p7r3-733m | high | | go | 1.17.6 | fixed in 1.17.7, 1.16.14 | 18-Nov-2019 00:00 | 21-Mar-2022 13:11
GHSA-q99m-p7hq-5v4f | high | | go | 1.17.6 | fixed in 1.17.7, 1.16.14 | 19-Jan-2022 00:00 | 21-Mar-2022 13:11

Signed-off-by: Yuan Tang [email protected]

@terrytangyuan terrytangyuan added the type/security Security related label Mar 23, 2022
@alexec
Copy link
Contributor

alexec commented Mar 23, 2022

Doesn't 1.17 give us the latest version always?

@terrytangyuan
Copy link
Member Author

Doesn't 1.17 give us the latest version always?

You are right. Although would it be better to be more explicit (like what Argo CD does), especially when releasing the images?

@alexec
Copy link
Contributor

alexec commented Mar 23, 2022

i think it just creates work to re-pin the version

@terrytangyuan
Copy link
Member Author

That's a good point. Also cc @crenshaw-dev who's working on upgrading this as well. Any downside of always using the latest version via 1.17 that you can think of?

@crenshaw-dev
Copy link
Member

@terrytangyuan good point. I think we can just use latest. I'll try that on the other PR.

@terrytangyuan terrytangyuan deleted the bump-go-version branch March 23, 2022 17:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
type/security Security related
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants