Skip to content

PROJQUAY-9434: updated go version to 1.24.9 for CVE-2025-47907#2322

Closed
rhdmalone wants to merge 2 commits intoquay:mainfrom
rhdmalone:main
Closed

PROJQUAY-9434: updated go version to 1.24.9 for CVE-2025-47907#2322
rhdmalone wants to merge 2 commits intoquay:mainfrom
rhdmalone:main

Conversation

@rhdmalone
Copy link
Contributor

No description provided.

@rhdmalone rhdmalone requested a review from a team as a code owner November 3, 2025 11:53
@rhdmalone rhdmalone requested review from hdonnay and removed request for a team November 3, 2025 11:53
Copy link
Member

@hdonnay hdonnay left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

In the commit message, please use a descriptive prefix like deps: or go.mod: instead of PROJQUAY-9434:.

The change in config/go.mod is unneeded and should be removed.

cubismod and others added 2 commits November 3, 2025 16:42
Signed-off-by: Ryan Wallace <rywallac@redhat.com>
Signed-off-by: Deirdre Malone <dmalone@redhat.com>
PROJQUAY-9434: Upgraded Go from 1.24.0 to 1.24.9 to address
security vulnerability CVE-2025-47907 in the crypto/x509 package.
Updated both main go.mod and config/go.mod files.

Signed-off-by: Deirdre Malone <dmalone@redhat.com>
@rhdmalone rhdmalone closed this by deleting the head repository Nov 3, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

3 participants