Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Critical security vulnerability in go 1.21.10 #45

Closed
kirach opened this issue Jun 27, 2024 · 1 comment
Closed

Critical security vulnerability in go 1.21.10 #45

kirach opened this issue Jun 27, 2024 · 1 comment

Comments

@kirach
Copy link

kirach commented Jun 27, 2024

Hi there,

We're using the latest version of secrets-init (0.5.2) in our docker containers to fetch secrets from google cloud (we also store our docker containers in gcp). And google cloud security scanner started to report critical security vulnerabilitiy in our docker images which turned out to be related to the version of go used in the latest secrets-init which is 1.21.10.

Here is the link to the security vulnerability,

The issue should be fixed in go 1.21.11. Based on what I see in the Dockerfile no code changes are needed, it should be enough to rebuild the docker image and it should switch to the latest version of go.

Thank you for you work and let me know if I can provide any additional information.

@alexei-led
Copy link
Collaborator

switched to go 1.22

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants