From 7352410f93c771abe74326c1e40e295d2ab69f16 Mon Sep 17 00:00:00 2001 From: NiniOak Date: Tue, 10 Sep 2024 17:36:17 +0000 Subject: [PATCH 1/2] backport of commit 9f290754da387140cd8eee8ab0ac5ebdc4f40e4a --- .go-version | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.go-version b/.go-version index da9594fd66..87b26e8b1a 100644 --- a/.go-version +++ b/.go-version @@ -1 +1 @@ -1.22.5 +1.22.7 From c17fa0ef85ad9b4e2e79fab730037692cf32dabe Mon Sep 17 00:00:00 2001 From: NiniOak Date: Tue, 10 Sep 2024 18:32:12 +0000 Subject: [PATCH 2/2] backport of commit 430864e21c81a7facb428e59c2d3d12337300b1b --- .changelog/4313.txt | 4 ++++ 1 file changed, 4 insertions(+) create mode 100644 .changelog/4313.txt diff --git a/.changelog/4313.txt b/.changelog/4313.txt new file mode 100644 index 0000000000..e6ab5ba811 --- /dev/null +++ b/.changelog/4313.txt @@ -0,0 +1,4 @@ +```release-note:security +Upgrade Go to use 1.22.7. This addresses CVE +[CVE-2024-34155](https://nvd.nist.gov/vuln/detail/CVE-2024-34155) +``` \ No newline at end of file