Skip to content

Update Go to 1.24.10 to fix multiple CVEs (including High severity) #1841

@ErickRDS

Description

@ErickRDS

Our security scanners are flagging the current opm image because it is built with a vulnerable Go version. The following Go-related CVEs are being reported: CVE-2025-47912, CVE-2025-58183, CVE-2025-58185, CVE-2025-58186, CVE-2025-58188, CVE-2025-58189, CVE-2025-61723, CVE-2025-61724, and CVE-2025-61725. At least two of these are classified as High severity by our scanners, which blocks us from passing internal security checks. We would like to request that opm be rebuilt using Go 1.24.10 (or newer in the 1.24 line), updating the go/toolchain configuration accordingly, and that a new release be published so we can update our deployment and clear these findings.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions