Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump Go version from 1.18 to 1.19/1.20 #7066

Closed
Bjyothi2023 opened this issue Sep 13, 2023 · 5 comments
Closed

Bump Go version from 1.18 to 1.19/1.20 #7066

Bjyothi2023 opened this issue Sep 13, 2023 · 5 comments

Comments

@Bjyothi2023
Copy link

Vulnerability scanner over Eksctl binary is reporting multiple vulnerabilities because of Go version 1.18.10 and the fix is available in 1.20.5, 1.19.10

List of vulnerabilities reported are :
GHSA-876p-8259-xjgg
GHSA-68g3-2p3g-w9pq
GHSA-3q6h-q44p-xw88
GHSA-9f7g-gqwh-jpf5
GHSA-c9hr-fvm9-7c49
GHSA-v4m2-x4rp-hv22
GHSA-vvpx-j8f3-3w6h
GHSA-888h-rm2r-vrc7
GHSA-rxx3-4978-3cc9
GHSA-7qhm-5mxq-x7vp
GHSA-f8f7-69v5-w4vx
GHSA-x2w5-7wp4-5qff
GHSA-xc82-5m89-g4jv

Eksctl version used: v0.156.0

Resolution: Bump Go version to either 1.20/1.19

@github-actions
Copy link
Contributor

Hello Bjyothi2023 👋 Thank you for opening an issue in eksctl project. The team will review the issue and aim to respond within 1-5 business days. Meanwhile, please read about the Contribution and Code of Conduct guidelines here. You can find out more information about eksctl on our website

@Himangini
Copy link
Collaborator

We are aware of this issue with Go, Please read our security policy here https://github.com/eksctl-io/eksctl/security/policy

@Himangini Himangini closed this as not planned Won't fix, can't repro, duplicate, stale Sep 13, 2023
@Bjyothi2023
Copy link
Author

@Himangini , when are you planning to resolve this issue if you are aware of it already

@cPu1
Copy link
Collaborator

cPu1 commented Sep 19, 2023

@Bjyothi2023, this is now fixed, the changes will be out in the next release candidate this week.

@Bjyothi2023
Copy link
Author

Thank you very much.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants