Skip to content

Conversation

@cowbon
Copy link
Collaborator

@cowbon cowbon commented Jan 7, 2026

Upgrade golang.org/x/crypto version to address advisories
CVE-2025-47913
CVE-2025-47914
CVE-2025-58181

cowbon added 2 commits January 7, 2026 17:44
As of Jan 2026, most Fedora-like OSes support go 1.24 or newer, and
newer versions of dependencies start to require go 1.23. As the result,
revert the commit that rolls back to the prior golang version, and use
golang 1.24 instead

Signed-off-by: Ian Chin Wang <[email protected]>
Upgrade golang.org/x/crypto version to address advisories
[CVE-2025-47913](GHSA-56w8-48fp-6mgv)
[CVE-2025-47914](GHSA-f6x5-jh6r-wrfv)
[CVE-2025-58181](GHSA-j5w8-q4qc-rx2x)

Signed-off-by: Ian Chin Wang <[email protected]>
Copy link
Collaborator

@jraman567 jraman567 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM! Thanks Tom.

@cowbon cowbon merged commit 0851e95 into main Jan 12, 2026
2 checks passed
@cowbon cowbon deleted the cve-fix branch January 12, 2026 16:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants