Skip to content

Please upgrade GO and release new version, to fix security issues #1014

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed
bartoszkosiorek opened this issue Mar 21, 2025 · 3 comments
Closed
Labels
backlog candidate Pull requests/issues that are candidates to be backlog items community Issues or PRs opened by an external contributor

Comments

@bartoszkosiorek
Copy link

bartoszkosiorek commented Mar 21, 2025

Describe the bug
Please upgrade Go to 1.23.5 and release new version, to fix security issues.

It is already fixed with commit:
e3c6abe

It is resolving:
https://www.suse.com/security/cve/CVE-2025-22868.html
https://www.suse.com/security/cve/CVE-2025-22869.html
https://www.suse.com/security/cve/CVE-2025-22870.html

The Go needs to be upgraded (issues was resolved with Go - 1.23.5):
https://www.suse.com/security/cve/CVE-2024-45336.html
https://www.suse.com/security/cve/CVE-2024-45341.html
https://www.suse.com/security/cve/CVE-2025-22866.html

More information about fixes in Go fixes:
golang/go@fdb8413
golang/go@bb8230f

Copy link

nginx-bot bot commented Mar 21, 2025

Hi @bartoszkosiorek! Welcome to the project! 🎉

Thanks for opening this issue!
Be sure to check out our Contributing Guidelines and the Issue Lifecycle while you wait for someone on the team to take a look at this.

@nginx-bot nginx-bot bot added the community Issues or PRs opened by an external contributor label Mar 21, 2025
@bartoszkosiorek bartoszkosiorek changed the title Please release new version, to fix security issues Please upgrade GO and release new version, to fix security issues Mar 21, 2025
@jjngx
Copy link
Contributor

jjngx commented Mar 25, 2025

@bartoszkosiorek there are no vulnerabilities:

➜  nginx-prometheus-exporter git:(main) govulncheck ./...
No vulnerabilities found.
➜  nginx-prometheus-exporter git:(main) govulncheck -version
Go: go1.24.1
Scanner: [email protected]
DB: https://vuln.go.dev
DB updated: 2025-03-18 18:14:48 +0000 UTC

No vulnerabilities found.

Please use Go version 1.24.1 or latest from 1.23.x line for compiling the binary.

We will be tagging new version soon. Please track work progress here: #1024

@jjngx jjngx added the backlog candidate Pull requests/issues that are candidates to be backlog items label Mar 25, 2025
@mpstefan
Copy link
Member

Fixed by Renovate PR

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
backlog candidate Pull requests/issues that are candidates to be backlog items community Issues or PRs opened by an external contributor
Projects
None yet
Development

No branches or pull requests

3 participants