Skip to content

Update Go version used to build releases #46

Description

@russjury

Golang 1.17.1 (used for latest build 0.2.1) has several critical vulnerabilities (CVEs), and would be nice to use a more current version if possible for pre-built binaries (I'm lazy and I assume there are many others as well). I know it's a never-ending battle, but since this is used in Microsoft's azure-cli container this way (which uses a WAY older version, but that's another story -- and I can't fix that (easily) until this is resolved), I'm hoping this is easy and controversy-free. Thanks.

Currently Go 1.19.9+ or 1.20.4+ would be needed to be "Critical-CVE-free".

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions