-
Notifications
You must be signed in to change notification settings - Fork 9.8k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Bump Go version to 1.21.5 to address CVE-2023-39326 #17049
Comments
cc: @jmhbnz @ahrtr @serathius |
1.21.5 and 1.20.12 are not available yet. |
@ahrtr True. They are likely to be available on December 5. This issue is in anticipation of the changes required once 1.21.5 and 1.20.15 are available. |
1.21.5 and 1.20.12 has now dropped: https://go.dev/doc/devel/release#go1.21.0
Let's update asap given security fixes, completion tracking below:
|
Hey @jmhbnz, I can work on bbolt and raft (I'm currently working on another PR on etcd and want to finish that before committing to anything in that repo). |
That would be great thanks @ivanvc. Added you to the assignees for this issue 🙏🏻 |
@jmhbnz I can also update the |
Thanks @ivanvc would you be able to raise raft one please? New contributor @jonasrdl raised the pr for |
Yes, I'm currently working on it. |
Sure, I'll do |
Closing - All updates completed and changelog updated, thanks to everyone that helped 🙏🏻 |
What would you like to be added?
The Go team has pre-announced release of 1.21.5 on December 5. This is a security release and fixes the CVE:
This issue has been created to work on etcd fixes in anticipation of the upcoming go release.
Why is this needed?
To make sure that CVE-2023-39326 is addressed and fixed.
The text was updated successfully, but these errors were encountered: