Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade the version of Go for next release of Sensu Go #5086

Open
jhenderson-pro opened this issue Feb 10, 2025 · 0 comments
Open

Upgrade the version of Go for next release of Sensu Go #5086

jhenderson-pro opened this issue Feb 10, 2025 · 0 comments
Assignees
Labels
dependencies Pull requests that update a dependency file low hanging 🍇 Things that are relatively easy to solve
Milestone

Comments

@jhenderson-pro
Copy link
Member

There are known vulnerabilities in the version of Go presently utilized in the latest version of Sensu Go 6.12.0

vulnerability_name source source name version fixed_version
CVE-2024-45338 GHSA-w32m-9786-jp63 LIBRARY golang.org/x/net 0.23.0 0.33.0
CVE-2024-0406 GHSA-rhh4-rh7c-7r5v LIBRARY github.com/mholt/archiver/v3 3.3.1-0.20191129193105-44285f7ed244
CVE-2024-51744 GHSA-29wx-vh33-7x7r LIBRARY github.com/golang-jwt/jwt/v4 4.5.0 4.5.1

Possible Solution

Please include the latest version of Go (and other dependencies) in the next release of Sensu Go

@jhenderson-pro jhenderson-pro added this to the 6.12.1 milestone Feb 10, 2025
@jhenderson-pro jhenderson-pro added low hanging 🍇 Things that are relatively easy to solve dependencies Pull requests that update a dependency file labels Feb 10, 2025
@ManishaKumari295 ManishaKumari295 self-assigned this Feb 11, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file low hanging 🍇 Things that are relatively easy to solve
Projects
None yet
Development

No branches or pull requests

2 participants