Skip to content

fix(deps): patch security vulnerability#66

Merged
lsy357 merged 3 commits into
coze-dev:mainfrom
wsx864321:chore/deps/security-batch-update-20250731
Aug 19, 2025
Merged

fix(deps): patch security vulnerability#66
lsy357 merged 3 commits into
coze-dev:mainfrom
wsx864321:chore/deps/security-batch-update-20250731

Conversation

@wsx864321
Copy link
Copy Markdown
Contributor

[fix][deps]: patch security vulnerability

What type of PR is this?

fix security vulnerability & upgrade go version

Check the PR title.

  • This PR title match the format: (optional scope):

(Optional) Translate PR title

[fix][deps|go]:

  • 升级go版本 go 1.23.5 -> go 1.24.0
  • 修复 github.com/expr-lang/expr v1.15.8 中的安全漏洞 CVE-2025-29786
  • 修复 github.com/ollama/ollama v0.5.12 中的安全漏洞 CVE-2024-12886
  • 修复 github.com/ollama/ollama v0.5.12 中的安全漏洞 CVE-2024-8063
  • 修复 github.com/ollama/ollama v0.5.12 中的安全漏洞 CVE-2024-0317
  • 修复 github.com/ollama/ollama v0.5.12 中的安全漏洞 CVE-2024-0315
  • 修复 github.com/ollama/ollama v0.5.12 中的安全漏洞 CVE-2025-51471

@CLAassistant
Copy link
Copy Markdown

CLAassistant commented Jul 31, 2025

CLA assistant check
All committers have signed the CLA.

@CLAassistant
Copy link
Copy Markdown

CLA assistant check
Thank you for your submission! We really appreciate it. Like many open source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution.
You have signed the CLA already but the status is still pending? Let us recheck it.

@lsy357
Copy link
Copy Markdown
Collaborator

lsy357 commented Aug 1, 2025

Hi, we need some time to evaluate it because the PR changed the Go version. Thank you for raising the issue!

@wsx864321
Copy link
Copy Markdown
Contributor Author

Hi, we need some time to evaluate it because the PR changed the Go version. Thank you for raising the issue!

ok

@lsy357
Copy link
Copy Markdown
Collaborator

lsy357 commented Aug 15, 2025

Thanks for your code! Based on your suggestion, we have upgraded the Go version and Docker image. Please rebase the latest code and push.

@wsx864321
Copy link
Copy Markdown
Contributor Author

Thanks for your code! Based on your suggestion, we have upgraded the Go version and Docker image. Please rebase the latest code and push.

ok,I have merged main,please review,thx

Comment thread backend/go.mod
@wsx864321 wsx864321 force-pushed the chore/deps/security-batch-update-20250731 branch 3 times, most recently from a1a4cdc to 93f4c34 Compare August 19, 2025 13:39
@lsy357
Copy link
Copy Markdown
Collaborator

lsy357 commented Aug 19, 2025

It seems that the version of ollama which eino depends on is incorrect. Running go get github.com/cloudwego/eino-ext/components/model/ollama can resolve the build issue.

@wsx864321
Copy link
Copy Markdown
Contributor Author

It seems that the version of ollama which eino depends on is incorrect. Running go get github.com/cloudwego/eino-ext/components/model/ollama can resolve the build issue.

ok.Resolved.thx

@lsy357 lsy357 merged commit 71d02ac into coze-dev:main Aug 19, 2025
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants