[Dependencies] Bump go version to 1.23#37
Conversation
liranbg
left a comment
There was a problem hiding this comment.
Please do change to 1.23 rather than mention specific patch version
we would like to get latest patch security updates if possible
|
@liranbg The Go version specified in the go.mod file should include the patch version to ensure compatibility with the project's dependencies. If you specify only the major and minor version (e.g., go 1.23), Go may interpret this as a "unreleased" version or as a broader requirement that could lead to unexpected issues or errors. it is generally not a recommended way. |
For project small enough, such as below - this should not be an issue. for large-scale projects where dependencies may very between OS / Arch and etc, it may be more accurate. the overhead of bumping patch every security cycle perhaps should be more easy and therefore my suggestion |
Jira - https://iguazio.atlassian.net/browse/IG-23655, https://iguazio.atlassian.net/browse/IG-23595