Skip to content

Cherrypick commits for 0.9.1#1553

Closed
coderbirju wants to merge 2 commits into
awslabs:release/0.9from
coderbirju:patch-v0.9.0
Closed

Cherrypick commits for 0.9.1#1553
coderbirju wants to merge 2 commits into
awslabs:release/0.9from
coderbirju:patch-v0.9.0

Conversation

@coderbirju
Copy link
Copy Markdown
Contributor

@coderbirju coderbirju commented May 7, 2025

This PR cherrypicks and backports two commits

Issue #, if available:

Description of changes:

Testing performed:

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.

This is a manual dependency bump to patch CVE GO-2025-3595, since our
automated script doesn't auto-bump indirect dependencies.

https://pkg.go.dev/vuln/GO-2025-3595

Signed-off-by: David Son <davbson@amazon.com>
@coderbirju coderbirju requested a review from a team as a code owner May 7, 2025 19:54
GitHub is removing ubuntu 20.04 hosted runners on April 15. This bumps
all of our runners to 22.04

The most significant change for us is that ubuntu 22.04 uses libc 2.34
which will be used in our release artifacts and may not be compatible
with older systems (e.g. AL2). For affected customers, we also ship a
statically linked binary, so this should have minimal impact.

Signed-off-by: Kern Walster <walster@amazon.com>
@coderbirju coderbirju changed the title Update golang.org/x/net to v0.39.0 Cherrypick commits for 0.9.1 May 7, 2025
@coderbirju
Copy link
Copy Markdown
Contributor Author

Closing this as the team decided to not include these changes upstream

@coderbirju coderbirju closed this May 12, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants