Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

crane: Bump Go version from 1.18 to 1.19/1.20 #1785

Closed
Bjyothi2023 opened this issue Sep 13, 2023 · 5 comments · Fixed by #1840
Closed

crane: Bump Go version from 1.18 to 1.19/1.20 #1785

Bjyothi2023 opened this issue Sep 13, 2023 · 5 comments · Fixed by #1840
Labels
bug Something isn't working

Comments

@Bjyothi2023
Copy link

Vulnerability scanner over Crane binary is reporting multiple vulnerabilities because of Go version 1.18.10 and the fix is available in 1.20.5, 1.19.10

List of vulnerabilities reported are :
CVE-2023-39533
CVE-2023-29405
CVE-2023-24539
CVE-2023-24536
CVE-2023-29400
CVE-2023-24538
CVE-2022-41723
CVE-2023-29404
CVE-2023-29403
CVE-2023-24540
CVE-2023-29406
CVE-2023-24532
CVE-2023-29409

Crane version used: v0.16.1

Resolution: Bump Go version to either 1.20/1.19

@Bjyothi2023 Bjyothi2023 added the bug Something isn't working label Sep 13, 2023
@dosilyoun
Copy link

dosilyoun commented Oct 5, 2023

Can we get a high prio for this?

@Bjyothi2023
Copy link
Author

Any update on this issue?

@Bjyothi2023
Copy link
Author

Adding one more vunerability to this issue : CVE-2023-39323

@Bjyothi2023
Copy link
Author

Hi Team, when we would expect for these changes to be released

@Bjyothi2023
Copy link
Author

Team,

I could see changes are pushed for this issue, but when can we expect a new release with these changes.
You can unblock us only by providing a new release with these changes soon.
Please help in releasing new release on top of 0.16.1

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants