Commit 5344650
authored
fix: upgrade Go to 1.25.12 (#12602)
fix: upgrade Go to 1.25.12 (CVE-2026-39822)
The release image Trivy scan blocks on CVE-2026-39822 in the Go stdlib
(os.Root symlink following / directory traversal, HIGH), present in the
Go 1.25.11 binary and fixed in 1.25.12.
Bump the go directive in go.mod to 1.25.12 (this drives the golang-alpine
build image the docker-build job derives from go.mod) and update the
pinned GOLANG_BUILD_IMAGE in release.yml to the matching 1.25.12 digest.
Signed-off-by: Julian Koberg <julian.koberg@kiteworks.com>1 parent 8481d02 commit 5344650
3 files changed
Lines changed: 10 additions & 2 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
16 | 16 | | |
17 | 17 | | |
18 | 18 | | |
19 | | - | |
| 19 | + | |
20 | 20 | | |
21 | 21 | | |
22 | 22 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | 2 | | |
3 | | - | |
| 3 | + | |
4 | 4 | | |
5 | 5 | | |
6 | 6 | | |
| |||
0 commit comments