Skip to content

Backport of [NET-4865] security: Update Go version to 1.20.6 into release/1.15.x#18194

Merged
hc-github-team-consul-core merged 1 commit intorelease/1.15.xfrom
backport/zalimeni/net-4865-bump-go-cve/unduly-robust-sunbeam
Jul 19, 2023
Merged

Backport of [NET-4865] security: Update Go version to 1.20.6 into release/1.15.x#18194
hc-github-team-consul-core merged 1 commit intorelease/1.15.xfrom
backport/zalimeni/net-4865-bump-go-cve/unduly-robust-sunbeam

Conversation

@hc-github-team-consul-core
Copy link
Collaborator

Backport

This PR is auto-generated from #18190 to be assessed for backporting due to the inclusion of the label backport/1.15.

The below text is copied from the body of the original PR.


This resolves CVE-2023-29406 for uses of the net/http standard library.

Note that until the follow-up to #18124 is done, the version of Go used in those impacted tests will need to remain on 1.20.5.

See related PR for golang.org/x/net dependencies: #18186

Description

Resolves CVE and brings us up to the latest version of Go.

Testing & Reproduction steps

Tests should continue to pass.

Links

https://nvd.nist.gov/vuln/detail/CVE-2023-29406
https://go-review.googlesource.com/c/go/+/506996
https://go-review.googlesource.com/c/net/+/506995

PR Checklist

  • updated test coverage
  • external facing docs updated
  • appropriate backport labels added
  • not a security concern

Overview of commits

@hc-github-team-consul-core hc-github-team-consul-core requested a review from a team July 19, 2023 21:02
@hc-github-team-consul-core hc-github-team-consul-core requested a review from a team as a code owner July 19, 2023 21:02
@hc-github-team-consul-core hc-github-team-consul-core requested review from emilymianeil and shore and removed request for a team July 19, 2023 21:02
@hc-github-team-consul-core hc-github-team-consul-core force-pushed the backport/zalimeni/net-4865-bump-go-cve/unduly-robust-sunbeam branch from a799176 to 04baea2 Compare July 19, 2023 21:02
@hc-github-team-consul-core hc-github-team-consul-core force-pushed the backport/zalimeni/net-4865-bump-go-cve/unduly-robust-sunbeam branch from dcb4a5d to 4e19038 Compare July 19, 2023 21:02
@hc-github-team-consul-core hc-github-team-consul-core enabled auto-merge (squash) July 19, 2023 21:02
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Auto approved Consul Bot automated PR

@github-actions github-actions bot added type/ci Relating to continuous integration (CI) tooling for testing or releases theme/contributing Additions and enhancements to community contributing materials labels Jul 19, 2023
@vercel vercel bot temporarily deployed to Preview – consul-ui-staging July 19, 2023 21:06 Inactive
@vercel vercel bot temporarily deployed to Preview – consul July 19, 2023 21:08 Inactive
@hc-github-team-consul-core hc-github-team-consul-core merged commit 22189b6 into release/1.15.x Jul 19, 2023
@hc-github-team-consul-core hc-github-team-consul-core deleted the backport/zalimeni/net-4865-bump-go-cve/unduly-robust-sunbeam branch July 19, 2023 21:27
@atlassian atlassian bot mentioned this pull request Aug 28, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

theme/contributing Additions and enhancements to community contributing materials type/ci Relating to continuous integration (CI) tooling for testing or releases

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants