Skip to content

fix: bump go to 1.23.1#1091

Merged
ryanzhang-oss merged 1 commit intoAzure:mainfrom
zhiying-lin:upgrade-go
Mar 20, 2025
Merged

fix: bump go to 1.23.1#1091
ryanzhang-oss merged 1 commit intoAzure:mainfrom
zhiying-lin:upgrade-go

Conversation

@zhiying-lin
Copy link
Copy Markdown
Contributor

Description of your changes

fix cve

hubagent (gobinary)

Total: 1 (HIGH: 1, CRITICAL: 0)

┌─────────┬────────────────┬──────────┬────────┬───────────────────┬────────────────┬───────────────────────────────────────────────────────────┐
│ Library │ Vulnerability │ Severity │ Status │ Installed Version │ Fixed Version │ Title │
├─────────┼────────────────┼──────────┼────────┼───────────────────┼────────────────┼───────────────────────────────────────────────────────────┤
│ stdlib │ CVE-2024-34156 │ HIGH │ fixed │ v1.23.0 │ 1.22.7, 1.23.1 │ encoding/gob: golang: Calling Decoder.Decode on a message │
│ │ │ │ │ │ │ which contains deeply nested structures... │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2024-34156
└─────────┴────────────────┴──────────┴────────┴───────────────────┴────────────────┴───────────────────────────────────────────────────────────┘
https://github.com/Azure/fleet/actions/runs/13953668387/job/39059392762

-->

Fixes #

I have:

  • Run make reviewable to ensure this PR is ready for review.

How has this code been tested

Special notes for your reviewer

@ryanzhang-oss ryanzhang-oss merged commit 4620852 into Azure:main Mar 20, 2025
16 checks passed
@zhiying-lin zhiying-lin deleted the upgrade-go branch March 21, 2025 00:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants