Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

go: upgrade to 1.22.2 and grpc-go to latest #6297

Merged
merged 1 commit into from
Apr 4, 2024

Conversation

sluongng
Copy link
Contributor

@sluongng sluongng commented Apr 4, 2024

Address CVE-2023-45288

Upgraded grpc-go with

> go get google.golang.org/grpc@latest
go: upgraded cloud.google.com/go/compute v1.23.4 => v1.24.0
go: upgraded github.com/cncf/xds/go v0.0.0-20231109132714-523115ebc101 => v0.0.0-20231128003011-0fa0005c9caa
go: upgraded github.com/envoyproxy/go-control-plane v0.11.1 => v0.12.0
go: upgraded github.com/envoyproxy/protoc-gen-validate v1.0.2 => v1.0.4
go: upgraded github.com/golang/glog v1.1.2 => v1.2.0
go: upgraded github.com/google/uuid v1.5.0 => v1.6.0
go: upgraded github.com/prometheus/client_model v0.4.0 => v0.5.0
go: upgraded golang.org/x/oauth2 v0.16.0 => v0.17.0
go: upgraded google.golang.org/api v0.160.0 => v0.162.0
go: upgraded google.golang.org/genproto v0.0.0-20240205150955-31a09d347014 => v0.0.0-20240227224415-6ceb2ff114de
go: upgraded google.golang.org/genproto/googleapis/api v0.0.0-20240125205218-1f4bbc51befe => v0.0.0-20240227224415-6ceb2ff114de
go: upgraded google.golang.org/genproto/googleapis/bytestream v0.0.0-20240116215550-a9fa1716bcac => v0.0.0-20240125205218-1f4bbc51befe
go: upgraded google.golang.org/genproto/googleapis/rpc v0.0.0-20240205150955-31a09d347014 => v0.0.0-20240227224415-6ceb2ff114de
go: upgraded google.golang.org/grpc v1.61.0 => v1.63.0

also upgraded golang.org/x/net to v0.23.0 with

> go get golang.org/x/net@latest
go: upgraded golang.org/x/net v0.21.0 => v0.23.0

Address [CVE-2023-45288](https://www.kb.cert.org/vuls/id/421644)

Upgraded grpc-go with

```
> go get google.golang.org/grpc@latest
go: upgraded cloud.google.com/go/compute v1.23.4 => v1.24.0
go: upgraded github.com/cncf/xds/go v0.0.0-20231109132714-523115ebc101 => v0.0.0-20231128003011-0fa0005c9caa
go: upgraded github.com/envoyproxy/go-control-plane v0.11.1 => v0.12.0
go: upgraded github.com/envoyproxy/protoc-gen-validate v1.0.2 => v1.0.4
go: upgraded github.com/golang/glog v1.1.2 => v1.2.0
go: upgraded github.com/google/uuid v1.5.0 => v1.6.0
go: upgraded github.com/prometheus/client_model v0.4.0 => v0.5.0
go: upgraded golang.org/x/oauth2 v0.16.0 => v0.17.0
go: upgraded google.golang.org/api v0.160.0 => v0.162.0
go: upgraded google.golang.org/genproto v0.0.0-20240205150955-31a09d347014 => v0.0.0-20240227224415-6ceb2ff114de
go: upgraded google.golang.org/genproto/googleapis/api v0.0.0-20240125205218-1f4bbc51befe => v0.0.0-20240227224415-6ceb2ff114de
go: upgraded google.golang.org/genproto/googleapis/bytestream v0.0.0-20240116215550-a9fa1716bcac => v0.0.0-20240125205218-1f4bbc51befe
go: upgraded google.golang.org/genproto/googleapis/rpc v0.0.0-20240205150955-31a09d347014 => v0.0.0-20240227224415-6ceb2ff114de
go: upgraded google.golang.org/grpc v1.61.0 => v1.63.0
```

also upgraded golang.org/x/net to v0.23.0 with

```
> go get golang.org/x/net@latest
go: upgraded golang.org/x/net v0.21.0 => v0.23.0
```
@sluongng sluongng merged commit 8a2653f into master Apr 4, 2024
14 of 17 checks passed
@sluongng sluongng deleted the sluongng/upgrade-go-1.22.2 branch April 4, 2024 17:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

3 participants