Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump Go to 1.24.2 / 1.23.8 #19713

Open
12 of 17 tasks
henrybear327 opened this issue Apr 5, 2025 · 2 comments
Open
12 of 17 tasks

Bump Go to 1.24.2 / 1.23.8 #19713

henrybear327 opened this issue Apr 5, 2025 · 2 comments
Assignees
Labels
area/security priority/important-longterm Important over the long term, but may not be staffed and/or may need multiple releases to complete. type/feature

Comments

@henrybear327
Copy link
Contributor

henrybear327 commented Apr 5, 2025

What would you like to be added?

Golang 1.24.2 and 1.23.8 were released this week. According to our Dependency management documentation, we want to stay on the latest patch version. This means updating the release-3.4, release-3.5 and release-3.6 branches to 1.23.8 and main to 1.24.2.

This patch includes the security fix for CVE-2025-22871.

Progress track:

Please look at the previous issues and their pull requests, e.g., #19524 and #19333.

Why is this needed?

To keep the project up to date with the latest Go versions. And to address CVE-2025-22871.

@henrybear327 henrybear327 self-assigned this Apr 5, 2025
@ivanvc ivanvc added area/security priority/important-longterm Important over the long term, but may not be staffed and/or may need multiple releases to complete. labels Apr 5, 2025
henrybear327 added a commit to henrybear327/etcd that referenced this issue Apr 7, 2025
Reference:
- etcd-io#19713

Signed-off-by: Chun-Hung Tseng <[email protected]>
henrybear327 added a commit to henrybear327/etcd that referenced this issue Apr 7, 2025
Reference:
- etcd-io#19713

Signed-off-by: Chun-Hung Tseng <[email protected]>
henrybear327 added a commit to henrybear327/etcd that referenced this issue Apr 7, 2025
Reference:
- etcd-io#19713

Signed-off-by: Chun-Hung Tseng <[email protected]>
henrybear327 added a commit to henrybear327/etcd that referenced this issue Apr 7, 2025
Reference:
- etcd-io#19713

Signed-off-by: Chun-Hung Tseng <[email protected]>
henrybear327 added a commit to henrybear327/etcd that referenced this issue Apr 7, 2025
Reference:
- etcd-io#19713

Signed-off-by: Chun-Hung Tseng <[email protected]>
henrybear327 added a commit to henrybear327/etcd that referenced this issue Apr 7, 2025
Ran `go mod tidy` for all mod files manually.

Reference:
- etcd-io#19713

Signed-off-by: Chun-Hung Tseng <[email protected]>
@henrybear327
Copy link
Contributor Author

@joshjms Do you want to take the bbolt, raft, gofail, auger, etcd-operator, and protodoc part? :)

@joshjms
Copy link
Contributor

joshjms commented Apr 8, 2025

Sure!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
area/security priority/important-longterm Important over the long term, but may not be staffed and/or may need multiple releases to complete. type/feature
Development

No branches or pull requests

3 participants