Skip to content

Commit 9246c82

Browse files
committed
Upgrade Golang packages to mitigate CVE vulnerability
1 parent 224fbc0 commit 9246c82

98 files changed

Lines changed: 2542 additions & 1082 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

.circleci/config.yml

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -117,7 +117,7 @@ jobs:
117117
type: string
118118
default: ""
119119
docker:
120-
- image: cimg/go:1.24.10
120+
- image: cimg/go:1.24.11
121121
environment:
122122
PROVIDER: <<parameters.provider>>
123123
ARGS: <<parameters.args>>
@@ -136,14 +136,14 @@ jobs:
136136
when: always
137137
cleanup:
138138
docker:
139-
- image: cimg/go:1.24.10
139+
- image: cimg/go:1.24.11
140140
steps:
141141
- checkout
142142
- ci-dependencies
143143
- run: scripts/ci-cleanup
144144
cleanup_all:
145145
docker:
146-
- image: cimg/go:1.24.10
146+
- image: cimg/go:1.24.11
147147
steps:
148148
- checkout
149149
- ci-dependencies
@@ -157,14 +157,14 @@ jobs:
157157
repo:
158158
type: string
159159
docker:
160-
- image: cimg/go:1.24.10
160+
- image: cimg/go:1.24.11
161161
steps:
162162
- checkout
163163
- ci-dependencies
164164
- run: ci/deploy.sh <<parameters.repo>> <<parameters.app>> <<parameters.check>>
165165
test:
166166
docker:
167-
- image: cimg/go:1.24.10
167+
- image: cimg/go:1.24.11
168168
# working_directory: /go/src/github.com/convox/rack
169169
steps:
170170
- checkout
@@ -176,7 +176,7 @@ jobs:
176176
- run: curl -s https://codecov.io/bash | bash
177177
update:
178178
docker:
179-
- image: cimg/go:1.24.10
179+
- image: cimg/go:1.24.11
180180
steps:
181181
- checkout
182182
- ci-dependencies

.github/workflows/publish.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -15,7 +15,7 @@ jobs:
1515
uses: actions/checkout@v3
1616
with:
1717
fetch-depth: 0
18-
- name: golang-1.24.10
18+
- name: golang-1.24.11
1919
uses: actions/setup-go@v3
2020
- name: version
2121
run: echo "VERSION=${{ github.event.inputs.version }}" >> $GITHUB_ENV

.github/workflows/release.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -13,7 +13,7 @@ jobs:
1313
uses: actions/checkout@v3
1414
with:
1515
fetch-depth: 0
16-
- name: golang-1.24.10
16+
- name: golang-1.24.11
1717
uses: actions/setup-go@v3
1818
- name: go path
1919
run: |

Dockerfile

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
## package #####################################################################
22

3-
FROM golang:1.24.10-bookworm AS package
3+
FROM golang:1.24.11-bookworm AS package
44

55
# Add backports to get upx-ucl in Bookworm
66
RUN echo "deb http://deb.debian.org/debian bookworm-backports main" > /etc/apt/sources.list.d/backports.list && \

Dockerfile.arm

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
## package #####################################################################
22

3-
FROM golang:1.24.10 AS package
3+
FROM golang:1.24.11 AS package
44

55
# Add backports to get upx-ucl in Bookworm
66
RUN echo "deb http://deb.debian.org/debian bookworm-backports main" > /etc/apt/sources.list.d/backports.list && \

cmd/build/Dockerfile

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
FROM golang:1.24.10-bookworm AS package
1+
FROM golang:1.24.11-bookworm AS package
22

33
ENV PATH=$PATH:/go/bin
44

cmd/build/Dockerfile.arm

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
FROM golang:1.24.10-bookworm AS package
1+
FROM golang:1.24.11-bookworm AS package
22

33
ARG DOCKER_ARCH=aarch64
44
ENV PATH=$PATH:/go/bin

go.mod

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
module github.com/convox/rack
22

3-
go 1.24.10
3+
go 1.24.11
44

55
require (
66
github.com/RackSec/srslog v0.0.0-20170920152354-4d2c753a4ee1
@@ -36,7 +36,7 @@ require (
3636
github.com/stretchr/testify v1.9.0
3737
github.com/stvp/rollbar v0.5.1
3838
github.com/twmb/algoimpl v0.0.0-20170717182524-076353e90b94
39-
golang.org/x/crypto v0.38.0
39+
golang.org/x/crypto v0.46.0
4040
gopkg.in/cheggaaa/pb.v1 v1.0.28
4141
gopkg.in/yaml.v2 v2.4.0
4242
)
@@ -100,8 +100,8 @@ require (
100100
github.com/xtgo/uuid v0.0.0-20140804021211-a0b114877d4c // indirect
101101
golang.org/x/mod v0.22.0 // indirect
102102
golang.org/x/sync v0.10.0 // indirect
103-
golang.org/x/sys v0.33.0 // indirect
104-
golang.org/x/term v0.32.0 // indirect
103+
golang.org/x/sys v0.39.0 // indirect
104+
golang.org/x/term v0.38.0 // indirect
105105
golang.org/x/tools v0.29.0 // indirect
106106
gopkg.in/yaml.v3 v3.0.1 // indirect
107107
gotest.tools/v3 v3.5.2 // indirect

go.sum

Lines changed: 10 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -540,8 +540,8 @@ golang.org/x/crypto v0.0.0-20190102171810-8d7daa0c54b3/go.mod h1:6SG95UA2DQfeDnf
540540
golang.org/x/crypto v0.0.0-20190103213133-ff983b9c42bc/go.mod h1:6SG95UA2DQfeDnfUPMdvaQW0Q7yPrPDi9nlGo2tz2b4=
541541
golang.org/x/crypto v0.0.0-20190308221718-c2843e01d9a2/go.mod h1:djNgcEr1/C05ACkg1iLfiJU5Ep61QUkGW8qpdssI0+w=
542542
golang.org/x/crypto v0.0.0-20200117160349-530e935923ad/go.mod h1:LzIPMQfyMNhhGPhUkYOs5KpL4U8rLKemX1yGLhDgUto=
543-
golang.org/x/crypto v0.38.0 h1:jt+WWG8IZlBnVbomuhg2Mdq0+BBQaHbtqHEFEigjUV8=
544-
golang.org/x/crypto v0.38.0/go.mod h1:MvrbAqul58NNYPKnOra203SB9vpuZW0e+RRZV+Ggqjw=
543+
golang.org/x/crypto v0.46.0 h1:cKRW/pmt1pKAfetfu+RCEvjvZkA9RimPbh7bhFjGVBU=
544+
golang.org/x/crypto v0.46.0/go.mod h1:Evb/oLKmMraqjZ2iQTwDwvCtJkczlDuTmdJXoZVzqU0=
545545
golang.org/x/lint v0.0.0-20181026193005-c67002cb31c3/go.mod h1:UVdnD1Gm6xHRNCYTkRU2/jEulfH38KcIWyp/GAMgvoE=
546546
golang.org/x/lint v0.0.0-20190313153728-d0100b6bd8b3/go.mod h1:6SW0HCj/g11FgYtHlgUYUwCkIfeOF89ocIRzGO/8vkc=
547547
golang.org/x/mod v0.22.0 h1:D4nJWe9zXqHOmWqj4VMOJhvzj7bEZg4wEYa759z1pH4=
@@ -564,8 +564,8 @@ golang.org/x/net v0.0.0-20181220203305-927f97764cc3/go.mod h1:mL1N/T3taQHkDXs73r
564564
golang.org/x/net v0.0.0-20190311183353-d8887717615a/go.mod h1:t9HGtf8HONx5eT2rtn7q6eTqICYqUVnKs3thJo3Qplg=
565565
golang.org/x/net v0.0.0-20190404232315-eb5bcb51f2a3/go.mod h1:t9HGtf8HONx5eT2rtn7q6eTqICYqUVnKs3thJo3Qplg=
566566
golang.org/x/net v0.0.0-20190522155817-f3200d17e092/go.mod h1:HSz+uSET+XFnRR8LxR5pz3Of3rY3CfYBVs4xY44aLks=
567-
golang.org/x/net v0.34.0 h1:Mb7Mrk043xzHgnRM88suvJFwzVrRfHEHJEl5/71CKw0=
568-
golang.org/x/net v0.34.0/go.mod h1:di0qlW3YNM5oh6GqDGQr92MyTozJPmybPK4Ev/Gm31k=
567+
golang.org/x/net v0.47.0 h1:Mx+4dIFzqraBXUugkia1OOvlD6LemFo1ALMHjrXDOhY=
568+
golang.org/x/net v0.47.0/go.mod h1:/jNxtkgq5yWUGYkaZGqo27cfGZ1c5Nen03aYrrKpVRU=
569569
golang.org/x/oauth2 v0.0.0-20180821212333-d2e6202438be/go.mod h1:N/0e6XlmueqKjAGxoOufVs8QHGRruUQn6yWY3a++T0U=
570570
golang.org/x/sync v0.0.0-20180314180146-1d60e4601c6f/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM=
571571
golang.org/x/sync v0.0.0-20181108010431-42b317875d0f/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM=
@@ -599,13 +599,13 @@ golang.org/x/sys v0.0.0-20190422165155-953cdadca894/go.mod h1:h1NjWce9XRLGQEsW7w
599599
golang.org/x/sys v0.0.0-20210616094352-59db8d763f22/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
600600
golang.org/x/sys v0.0.0-20220715151400-c0bba94af5f8/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
601601
golang.org/x/sys v0.0.0-20220811171246-fbc7d0a398ab/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
602-
golang.org/x/sys v0.33.0 h1:q3i8TbbEz+JRD9ywIRlyRAQbM0qF7hu24q3teo2hbuw=
603-
golang.org/x/sys v0.33.0/go.mod h1:BJP2sWEmIv4KK5OTEluFJCKSidICx8ciO85XgH3Ak8k=
604-
golang.org/x/term v0.32.0 h1:DR4lr0TjUs3epypdhTOkMmuF5CDFJ/8pOnbzMZPQ7bg=
605-
golang.org/x/term v0.32.0/go.mod h1:uZG1FhGx848Sqfsq4/DlJr3xGGsYMu/L5GW4abiaEPQ=
602+
golang.org/x/sys v0.39.0 h1:CvCKL8MeisomCi6qNZ+wbb0DN9E5AATixKsvNtMoMFk=
603+
golang.org/x/sys v0.39.0/go.mod h1:OgkHotnGiDImocRcuBABYBEXf8A9a87e/uXjp9XT3ks=
604+
golang.org/x/term v0.38.0 h1:PQ5pkm/rLO6HnxFR7N2lJHOZX6Kez5Y1gDSJla6jo7Q=
605+
golang.org/x/term v0.38.0/go.mod h1:bSEAKrOT1W+VSu9TSCMtoGEOUcKxOKgl3LE5QEF/xVg=
606606
golang.org/x/text v0.3.0/go.mod h1:NqM8EUOU14njkJ3fqMW+pc6Ldnwhi/IjpwHt7yyuwOQ=
607-
golang.org/x/text v0.25.0 h1:qVyWApTSYLk/drJRO5mDlNYskwQznZmkpV2c8q9zls4=
608-
golang.org/x/text v0.25.0/go.mod h1:WEdwpYrmk1qmdHvhkSTNPm3app7v4rsT8F2UD6+VHIA=
607+
golang.org/x/text v0.32.0 h1:ZD01bjUt1FQ9WJ0ClOL5vxgxOI/sVCNgX1YtKwcY0mU=
608+
golang.org/x/text v0.32.0/go.mod h1:o/rUWzghvpD5TXrTIBuJU77MTaN0ljMWE47kxGJQ7jY=
609609
golang.org/x/time v0.0.0-20190308202827-9d24e82272b4/go.mod h1:tRJNPiyCQ0inRvYxbN9jk5I+vvW/OXSQhTDSoE431IQ=
610610
golang.org/x/tools v0.0.0-20180221164845-07fd8470d635/go.mod h1:n7NCudcB/nEzxVGmLbDWY5pfWTLqBcC2KZ6jyYvM4mQ=
611611
golang.org/x/tools v0.0.0-20180917221912-90fa682c2a6e/go.mod h1:n7NCudcB/nEzxVGmLbDWY5pfWTLqBcC2KZ6jyYvM4mQ=

vendor/golang.org/x/crypto/chacha20/chacha_arm64.s

Lines changed: 1 addition & 1 deletion
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

0 commit comments

Comments
 (0)