Update go toolchain to 1.22.6 [CVE-2024-24790 - 9.8 CVSS] by snowamk · Pull Request #1577 · fluxcd/source-controller

Skip to content

Navigation Menu

Sign in

Appearance settings

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up

Appearance settings

Conversation

@snowamk

Copy link Copy Markdown

@snowamk snowamk commented

Aug 14, 2024

To fix https://nvd.nist.gov/vuln/detail/CVE-2024-24790 / https://pkg.go.dev/vuln/GO-2024-2887

Full disclosure: Running into some issues with the tests timing out, but I'm hoping it's just my laptop cosplaying as a toaster and it'll run fine on your CI : /

@stefanprodan

Copy link Copy Markdown

Member

There is no need to bump the Go version in go.mod, when we will be releasing the controller we'll be using Go 1.23

@snowamk

Copy link Copy Markdown

Author

snowamk commented

Aug 15, 2024

Thanks @stefanprodan - any rough timeline for when the next image will be released with 1.23?

@stefanprodan

Copy link Copy Markdown

Member

Some weeks from now, when all things on the roadmap for Flux 2.4 will be finished https://fluxcd.io/roadmap/#v24-q3-2024

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Reviewers

No reviews

Assignees

No one assigned

Labels

None yet

Projects

None yet

Milestone

No milestone

Development

Successfully merging this pull request may close these issues.

2 participants

@snowamk @stefanprodan