Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

build: update to go1.22.5 #23498

Merged
merged 2 commits into from
Jul 3, 2024
Merged

build: update to go1.22.5 #23498

merged 2 commits into from
Jul 3, 2024

Conversation

dduzgun-security
Copy link
Collaborator

Update Go toolchain to 1.22.5 which addresses:

  • CVE-2024-24791 net/http: denial of service due to improper 100-continue handling

@dduzgun-security dduzgun-security added theme/security theme/build-infrastructure backport/ent/1.6.x+ent Changes are backported to 1.6.x+ent backport/ent/1.7.x+ent Changes are backported to 1.7.x+ent backport/ent/1.8.x+ent Changes are backported to 1.8.x+ent backport/1.8.x backport to 1.8.x release line labels Jul 3, 2024
Copy link
Member

@tgross tgross left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@dduzgun-security can you run make cl to add a changelog entry for this? Normally we wouldn't bother with toolchain updates, but having the CVE listed in the changelog makes it easier for folks to determine which versions of Nomad have the fix.

@tgross tgross removed the backport/ent/1.8.x+ent Changes are backported to 1.8.x+ent label Jul 3, 2024
@tgross
Copy link
Member

tgross commented Jul 3, 2024

I've removed the backport/1.8.x+ent label because that'll get merged over from the release/1.8.x on the nightly merge.

@dduzgun-security
Copy link
Collaborator Author

@tgross thanks for the review and adjusting the labels, I added the changelog 👍

Copy link
Member

@tgross tgross left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!

@tgross tgross merged commit 441f8f2 into main Jul 3, 2024
19 checks passed
@tgross tgross deleted the go1.22.5 branch July 3, 2024 19:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
backport/ent/1.6.x+ent Changes are backported to 1.6.x+ent backport/ent/1.7.x+ent Changes are backported to 1.7.x+ent backport/1.8.x backport to 1.8.x release line theme/build-infrastructure theme/security
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants