Skip to content

Commit 0f3cbbc

Browse files
LucasRoesleralexellis
authored andcommitted
Bump go version to 1.11.13
**What** - Using the base golang:1.11 docker image so that we can easily track security patches for go 1.11. In particular this includes go 1.11.13, which address https://groups.google.com/forum/#!topic/golang-announce/65QixT3tcmg > net/http: Denial of Service vulnerabilities in the HTTP/2 implementation > > net/http and golang.org/x/net/http2 servers that accept direct connections > from untrusted clients could be remotely made to allocate an unlimited amount > of memory, until the program crashes. Servers will now close connections if > the send queue accumulates too many control messages. > > net/url: parsing validation issue > > url.Parse would accept URLs with malformed hosts, such that the Host field > could have arbitrary suffixes that would appear in neither Hostname() nor > Port(), allowing authorization bypasses in certain applications. Note that URLs > with invalid, not numeric ports will now return an error from url.Parse. Signed-off-by: Lucas Roesler <[email protected]>
1 parent 28449bb commit 0f3cbbc

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

Dockerfile

+1-1
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
FROM golang:1.10
1+
FROM golang:1.11
22

33
RUN mkdir -p /go/src/github.com/openfaas-incubator/of-watchdog
44
WORKDIR /go/src/github.com/openfaas-incubator/of-watchdog

0 commit comments

Comments
 (0)