-
-
Notifications
You must be signed in to change notification settings - Fork 41
Bump Go to 1.24.10 to remove CVEs #215
Copy link
Copy link
Closed
Labels
component/builddependenciesPull requests that update a dependency filePull requests that update a dependency filekind/taskProject maintenance taskProject maintenance task
Milestone
Description
lbroudoux
opened on Nov 28, 2025
Issue body actions
| Severity | Vulnerability | CVSS score | Current package version | Fix version | CVE location |
|---|---|---|---|---|---|
| critical | CVE-2025-22871 | 9.1 | pkg:golang/[email protected] | 1.24.2 | Layer 22 |
| high | CVE-2025-58188 | 7.5 | pkg:golang/[email protected] | 1.24.8 | Layer 22 |
| high | CVE-2025-58187 | 7.5 | pkg:golang/[email protected] | 1.24.9 | Layer 22 |
| high | CVE-2025-61723 | 7.5 | pkg:golang/[email protected] | 1.24.8 | Layer 22 |
| high | CVE-2025-22874 | 7.5 | pkg:golang/[email protected] | 1.24.4 | Layer 22 |
| high | CVE-2025-61725 | 7.5 | pkg:golang/[email protected] | 1.24.8 | Layer 22 |
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
component/builddependenciesPull requests that update a dependency filePull requests that update a dependency filekind/taskProject maintenance taskProject maintenance task