Skip to content

Commit af1ef49

Browse files
committed
go: 1.20.4 and 1.19.9 to fix CVEs
Signed-off-by: Jason Hall <[email protected]>
1 parent e88321d commit af1ef49

File tree

4 files changed

+76
-12
lines changed

4 files changed

+76
-12
lines changed

go-1.19.yaml

Lines changed: 19 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
package:
22
name: go-1.19
3-
version: 1.19.8
4-
epoch: 1
3+
version: 1.19.9
4+
epoch: 0
55
description: "the Go programming language"
66
copyright:
77
- license: BSD-3-Clause
@@ -30,6 +30,10 @@ secfixes:
3030
- CVE-2023-24536
3131
- CVE-2023-24537
3232
- CVE-2023-24538
33+
1.19.9-r0:
34+
- CVE-2023-24539
35+
- CVE-2023-24540
36+
- CVE-2023-29400
3337

3438
environment:
3539
contents:
@@ -47,7 +51,7 @@ pipeline:
4751
- uses: fetch
4852
with:
4953
uri: https://go.dev/dl/go${{package.version}}.src.tar.gz
50-
expected-sha256: 1d7a67929dccafeaf8a29e55985bc2b789e0499cb1a17100039f084e3238da2f
54+
expected-sha256: 131190a4697a70c5b1d232df5d3f55a3f9ec0e78e40516196ffb3f09ae6a5744
5155
strip-components: 0
5256

5357
- runs: |
@@ -141,6 +145,18 @@ advisories:
141145
- timestamp: 2023-04-05T08:50:56.423606-04:00
142146
status: fixed
143147
fixed-version: 1.19.8-r0
148+
CVE-2023-24539:
149+
- timestamp: 2023-05-02T15:58:58.350831-04:00
150+
status: fixed
151+
fixed-version: 1.19.9-r0
152+
CVE-2023-24540:
153+
- timestamp: 2023-05-02T15:59:11.158232-04:00
154+
status: fixed
155+
fixed-version: 1.19.9-r0
156+
CVE-2023-29400:
157+
- timestamp: 2023-05-02T15:59:18.977361-04:00
158+
status: fixed
159+
fixed-version: 1.19.9-r0
144160

145161
update:
146162
enabled: true

go-1.20.yaml

Lines changed: 19 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
package:
22
name: go-1.20
3-
version: 1.20.3
4-
epoch: 1
3+
version: 1.20.4
4+
epoch: 0
55
description: "the Go programming language"
66
copyright:
77
- license: BSD-3-Clause
@@ -26,6 +26,10 @@ secfixes:
2626
- CVE-2023-24536
2727
- CVE-2023-24537
2828
- CVE-2023-24538
29+
1.20.4-r0:
30+
- CVE-2023-29400
31+
- CVE-2023-24539
32+
- CVE-2023-24540
2933

3034
environment:
3135
contents:
@@ -43,7 +47,7 @@ pipeline:
4347
- uses: fetch
4448
with:
4549
uri: https://go.dev/dl/go${{package.version}}.src.tar.gz
46-
expected-sha256: e447b498cde50215c4f7619e5124b0fc4e25fb5d16ea47271c47f278e7aa763a
50+
expected-sha256: 9f34ace128764b7a3a4b238b805856cc1b2184304df9e5690825b0710f4202d6
4751
strip-components: 0
4852

4953
- runs: |
@@ -133,6 +137,18 @@ advisories:
133137
- timestamp: 2023-04-05T08:50:58.537967-04:00
134138
status: fixed
135139
fixed-version: 1.20.3-r0
140+
CVE-2023-24539:
141+
- timestamp: 2023-05-02T16:01:15.588118-04:00
142+
status: fixed
143+
fixed-version: 1.20.4-r0
144+
CVE-2023-24540:
145+
- timestamp: 2023-05-02T16:01:15.623186-04:00
146+
status: fixed
147+
fixed-version: 1.20.4-r0
148+
CVE-2023-29400:
149+
- timestamp: 2023-05-02T16:01:15.651143-04:00
150+
status: fixed
151+
fixed-version: 1.20.4-r0
136152

137153
update:
138154
enabled: true

go-fips-1.19.yaml

Lines changed: 19 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
package:
22
name: go-fips-1.19
3-
version: 1.19.8
4-
epoch: 1
3+
version: 1.19.9
4+
epoch: 0
55
description: "the Go programming language with OpenSSL cryptography"
66
copyright:
77
- license: BSD-3-Clause
@@ -32,6 +32,10 @@ secfixes:
3232
- CVE-2023-24536
3333
- CVE-2023-24537
3434
- CVE-2023-24538
35+
1.19.9-r0:
36+
- CVE-2023-24540
37+
- CVE-2023-29400
38+
- CVE-2023-24539
3539

3640
environment:
3741
contents:
@@ -50,7 +54,7 @@ pipeline:
5054
- uses: fetch
5155
with:
5256
uri: https://go.dev/dl/go${{package.version}}.src.tar.gz
53-
expected-sha256: 1d7a67929dccafeaf8a29e55985bc2b789e0499cb1a17100039f084e3238da2f
57+
expected-sha256: 131190a4697a70c5b1d232df5d3f55a3f9ec0e78e40516196ffb3f09ae6a5744
5458
strip-components: 0
5559

5660
- working-directory: /home/build/go
@@ -153,6 +157,18 @@ advisories:
153157
- timestamp: 2023-04-05T08:55:40.609989-04:00
154158
status: fixed
155159
fixed-version: 1.19.8-r0
160+
CVE-2023-24539:
161+
- timestamp: 2023-05-02T15:59:47.675581-04:00
162+
status: fixed
163+
fixed-version: 1.19.9-r0
164+
CVE-2023-24540:
165+
- timestamp: 2023-05-02T15:59:58.258052-04:00
166+
status: fixed
167+
fixed-version: 1.19.9-r0
168+
CVE-2023-29400:
169+
- timestamp: 2023-05-02T16:00:05.929051-04:00
170+
status: fixed
171+
fixed-version: 1.19.9-r0
156172

157173
update:
158174
enabled: true

go-fips-1.20.yaml

Lines changed: 19 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
package:
22
name: go-fips-1.20
3-
version: 1.20.3
4-
epoch: 1
3+
version: 1.20.4
4+
epoch: 0
55
description: "the Go programming language with OpenSSL cryptography"
66
copyright:
77
- license: BSD-3-Clause
@@ -31,6 +31,10 @@ secfixes:
3131
- CVE-2023-24536
3232
- CVE-2023-24537
3333
- CVE-2023-24538
34+
1.20.4-r0:
35+
- CVE-2023-24540
36+
- CVE-2023-29400
37+
- CVE-2023-24539
3438

3539
environment:
3640
contents:
@@ -46,7 +50,7 @@ pipeline:
4650
- uses: fetch
4751
with:
4852
uri: https://go.dev/dl/go${{package.version}}.src.tar.gz
49-
expected-sha256: e447b498cde50215c4f7619e5124b0fc4e25fb5d16ea47271c47f278e7aa763a
53+
expected-sha256: 9f34ace128764b7a3a4b238b805856cc1b2184304df9e5690825b0710f4202d6
5054
strip-components: 0
5155

5256
- working-directory: /home/build/go
@@ -145,6 +149,18 @@ advisories:
145149
- timestamp: 2023-04-05T08:55:05.226339-04:00
146150
status: fixed
147151
fixed-version: 1.20.3-r0
152+
CVE-2023-24539:
153+
- timestamp: 2023-05-02T16:02:29.236055-04:00
154+
status: fixed
155+
fixed-version: 1.20.4-r0
156+
CVE-2023-24540:
157+
- timestamp: 2023-05-02T16:02:29.279148-04:00
158+
status: fixed
159+
fixed-version: 1.20.4-r0
160+
CVE-2023-29400:
161+
- timestamp: 2023-05-02T16:02:29.308339-04:00
162+
status: fixed
163+
fixed-version: 1.20.4-r0
148164

149165
update:
150166
enabled: true

0 commit comments

Comments
 (0)