Skip to content

Coraza 3.3.3 with CVE fix, tinygo 0.34#303

Merged
jcchavezs merged 3 commits intomainfrom
go_123_tiny_034_coraza_333
Apr 8, 2025
Merged

Coraza 3.3.3 with CVE fix, tinygo 0.34#303
jcchavezs merged 3 commits intomainfrom
go_123_tiny_034_coraza_333

Conversation

@M4tteoP
Copy link
Member

@M4tteoP M4tteoP commented Apr 7, 2025

This PR bumps Coraza to latest v3.3.3 in order to fix GHSA-q9f5-625g-xm39.

  • Tinygo 0.34 looks to most recent straightfoward tinygo version we can update to, and it is enough to support the required Go 1.23 for Coraza v3.3.3. Further work will be required to move to more recent versions.
  • A CRS Bump and new release will follow

@M4tteoP M4tteoP marked this pull request as ready for review April 7, 2025 22:47
@M4tteoP M4tteoP requested a review from jcchavezs as a code owner April 7, 2025 22:47
@jcchavezs jcchavezs merged commit b6accd0 into main Apr 8, 2025
4 checks passed
@M4tteoP M4tteoP deleted the go_123_tiny_034_coraza_333 branch April 8, 2025 13:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants