Skip to content

golang: bump to 1.24.12#2812

Merged
stevenhorsman merged 1 commit intoconfidential-containers:mainfrom
beraldoleal:go-bump-cve
Jan 30, 2026
Merged

golang: bump to 1.24.12#2812
stevenhorsman merged 1 commit intoconfidential-containers:mainfrom
beraldoleal:go-bump-cve

Conversation

@beraldoleal
Copy link
Copy Markdown
Member

Fixing GO-2026-4340 (crypto/tls) and GO-2026-4341 (net/url) standard library vulnerabilities.

@beraldoleal beraldoleal requested a review from a team as a code owner January 28, 2026 23:17
@beraldoleal
Copy link
Copy Markdown
Member Author

@stevenhorsman do we run the workflow manually to push the img or post merge?

@stevenhorsman
Copy link
Copy Markdown
Member

@stevenhorsman do we run the workflow manually to push the img or post merge?

The fedora-go image is only built on merging the Dockerfile.golang change, so we have to do this in two stages e.g. #2706 and #2707

Fixing GO-2026-4340 and GO-2026-4341.

Signed-off-by: Beraldo Leal <bleal@redhat.com>
Copy link
Copy Markdown
Member

@stevenhorsman stevenhorsman left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. Thanks @beraldoleal!

Copy link
Copy Markdown
Member

@wainersm wainersm left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

thanks @beraldoleal !

@wainersm
Copy link
Copy Markdown
Member

hi @beraldoleal , before we get this merged, could you send the PR to bump fedora-go?

@stevenhorsman stevenhorsman merged commit 1382392 into confidential-containers:main Jan 30, 2026
31 checks passed
@stevenhorsman
Copy link
Copy Markdown
Member

hi @beraldoleal , before we get this merged, could you send the PR to bump fedora-go?

I will just merge now to unblock things and if Beraldo isn't able to create part 2 I will later.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants