Skip to content

Conversation

@phyrog
Copy link
Collaborator

@phyrog phyrog commented Apr 9, 2024

Describe your changes

Update golang.org/x/net to v0.23.0 to fix https://osv.dev/vulnerability/GO-2024-2687

Go version has already been updated to 1.22.2, but x/net is still at the affected 0.22.0.

Issue ticket number and link

Checklist before requesting a review

  • I have performed a self-review of my code
  • If it is a core feature, I have added thorough tests.
  • I tested the changes with the following distributions:
    • Kind
    • MiniKube
    • MicroK8s
    • Rancher RKE2
    • Azure AKS
    • GCP GKE (Ubuntu nodes)
    • AWS EKS (AmazonLinux2 nodes)
    • AWS EKS (Ubuntu nodes)
    • Digital Ocean Kubernetes

@phyrog phyrog added go Pull requests that update Go code security Security related issues area/dependencies Pull requests that update a dependency file labels Apr 9, 2024
@voigt voigt merged commit 8403ff2 into main Apr 11, 2024
@voigt voigt deleted the update-x-net branch April 11, 2024 20:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/dependencies Pull requests that update a dependency file go Pull requests that update Go code security Security related issues

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants