Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Please update go version to 1.21.9 or 1.22.2 #1282

Closed
akoshok1 opened this issue Apr 22, 2024 · 3 comments · Fixed by #1336
Closed

Please update go version to 1.21.9 or 1.22.2 #1282

akoshok1 opened this issue Apr 22, 2024 · 3 comments · Fixed by #1336
Assignees

Comments

@akoshok1
Copy link

akoshok1 commented Apr 22, 2024

This is for CVE : GHSA-4v7x-pqxf-cx7m
This is for decK 1.37.

@Prashansa-K
Copy link
Contributor

@akoshok1 @mheap
The latest deck version (1.39) already uses 1.22.4.
If we do a patch release for 1.37 with this update, would we need to do the same for 1.38?

Also, prior versions (1.36 and lower) have 1.21 as well. Do we still support these or are these deprecated / EOL? How many simultaneous versions do we support at a time?

@mheap
Copy link
Member

mheap commented Jul 15, 2024

@Prashansa-K It looks like the release job uses 1.20 (see https://github.com/Kong/deck/blob/main/.github/workflows/release.yaml#L20)

We should update the jobs to read from go.mod and release a new version. Asking people to upgrade to latest is acceptable for deck

@Prashansa-K
Copy link
Contributor

This is fixed in 1.39.3

@Prashansa-K Prashansa-K added this to the next milestone Jul 23, 2024
@Prashansa-K Prashansa-K removed this from the next milestone Jul 31, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

3 participants