Skip to content

Conversation

@agenslerDNA
Copy link
Contributor

@agenslerDNA agenslerDNA commented Feb 11, 2025

This updates the dependencies to as most recent as possible to remove the vulnerability with glog documented here: https://pkg.go.dev/vuln/GO-2025-3372

  • Tests freeze with the just released bbolt 1.4.0, so this is updated to 1.3.11 instead
  • Updated this package to what the major dependencies also require, and to a supported version of Go
  • Latest badger no longer uses glog and avoids the vulnerability

go 1.13
go 1.23

toolchain go1.23.6
Copy link
Owner

@ostafen ostafen Feb 11, 2025

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sounds like the toolchain directive is causing a build issue

Copy link
Contributor Author

@agenslerDNA agenslerDNA Feb 11, 2025

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Oh, I did't see the workflow directory.

@ostafen ostafen merged commit 35f6fd3 into ostafen:v2 Feb 12, 2025
1 check passed
@agenslerDNA agenslerDNA deleted the CVE-2024-45339 branch February 12, 2025 15:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants