Skip to content

[20.10 backport] bump go 1.16.6, and remove Go version override from static builds#564

Merged
thaJeztah merged 4 commits intodocker:20.10from
thaJeztah:20.10_backport_bump_go_1.16.6
Jul 29, 2021
Merged

[20.10 backport] bump go 1.16.6, and remove Go version override from static builds#564
thaJeztah merged 4 commits intodocker:20.10from
thaJeztah:20.10_backport_bump_go_1.16.6

Conversation

@thaJeztah
Copy link
Member

backport of #563, and one commit from #554

Bump go 1.16.6 (addresses CVE-2021-34558)
This addresses CVE-2021-34558: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-34558

go1.16.6 (released 2021-07-12) includes a security fix to the crypto/tls package,
as well as bug fixes to the compiler, and the net and net/http packages. See the
Go 1.16.6 milestone on the issue tracker for details:

https://github.com/golang/go/issues?q=milestone%3AGo1.16.6+label%3ACherryPickApproved

Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
(cherry picked from commit 3d0e7c4)
Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
…m64"

This reverts commit 60e28c9, except for the
changes in plugins/app.installer

Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
Use the version that's defined/set in common.mk

Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
(cherry picked from commit 8141ee7)
Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
This addresses CVE-2021-34558: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-34558

go1.16.6 (released 2021-07-12) includes a security fix to the crypto/tls package,
as well as bug fixes to the compiler, and the net and net/http packages. See the
Go 1.16.6 milestone on the issue tracker for details:

https://github.com/golang/go/issues?q=milestone%3AGo1.16.6+label%3ACherryPickApproved

Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
(cherry picked from commit 9308b2f)
Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
Copy link

@djs55 djs55 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Also LGTM!

@thaJeztah thaJeztah merged commit aa7cffa into docker:20.10 Jul 29, 2021
@thaJeztah thaJeztah deleted the 20.10_backport_bump_go_1.16.6 branch July 29, 2021 11:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants