Skip to content

Conversation

florianl
Copy link
Member

@florianl florianl commented Mar 24, 2025

Mitigate CVE-2024-34158 by updating Go to 1.23.7.

More details on the CVE: https://pkg.go.dev/vuln/GO-2024-3107

Fixes #633

Mitigate CVE-2024-34158 by updating Go to 1.23.7.

Fixes #633

Signed-off-by: Florian Lehner <florian.lehner@elastic.co>
@github-actions github-actions bot added the aws-λ-extension AWS Lambda Extension label Mar 24, 2025
@florianl florianl enabled auto-merge (squash) March 24, 2025 15:18
@florianl florianl merged commit 25eb0c0 into main Mar 24, 2025
10 checks passed
@florianl florianl deleted the go-update-to-g-1.23.7 branch March 24, 2025 15:20
@hsharif-rh
Copy link

hsharif-rh commented Mar 25, 2025

Hey @florianl, when can we expect this to be reflected for the following layers:

FROM docker.elastic.co/observability/apm-lambda-extension-x86_64:latest AS lambda-extension
FROM docker.elastic.co/observability/apm-agent-nodejs:latest AS nodejs-agent

We've been seeing a lot of noise around vulnerabilities around Go. Do you have a rollout scheduled? Thank you.

@brett-fitz
Copy link

@florianl Can we get a bump on the release ^ to reduce noise in our vulnerability analysis tools?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

aws-λ-extension AWS Lambda Extension

Projects

None yet

Development

Successfully merging this pull request may close these issues.

CVE-2024-34158

4 participants