Skip to content

Modernize project to Go 1.25 and address security vulnerabilities - #225

Merged
snskArora merged 4 commits into
trstringer:mainfrom
snskArora:security/vulnerability_fix
Jun 27, 2026
Merged

snskArora merged 4 commits into
trstringer:mainfrom
snskArora:security/vulnerability_fix

Conversation

@snskArora

Copy link
Copy Markdown
Collaborator

GO version bumped, 1.24 -> 1.25 in order to bump crypto package 0.45 -> 0.53

Warn: Project is vulnerable to: GO-2026-5005
Warn: Project is vulnerable to: GO-2026-5006
Warn: Project is vulnerable to: GO-2026-5013
Warn: Project is vulnerable to: GO-2026-5014
Warn: Project is vulnerable to: GO-2026-5015
Warn: Project is vulnerable to: GO-2026-5016
Warn: Project is vulnerable to: GO-2026-5017
Warn: Project is vulnerable to: GO-2026-5018
Warn: Project is vulnerable to: GO-2026-5019
Warn: Project is vulnerable to: GO-2026-5020
Warn: Project is vulnerable to: GO-2026-5021
Warn: Project is vulnerable to: GO-2026-5023
Warn: Project is vulnerable to: GO-2026-5033

snskArora and others added 3 commits June 27, 2026 19:43
Updated Go base image to version 1.25 and removed image digest pinning for multi-architecture support.
@snskArora

snskArora commented Jun 27, 2026 •

Copy link
Copy Markdown
Collaborator Author

GO promises backward compatibility, and also, there are no changes between 1.24 and 1.25 that we are using in our action.

Tested with the new version in my org repos and it is working.

@lizziemac @beverts312
Please ping me in case of any concerns and I can revert this PR.

@snskArora
snskArora merged commit 8038731 into trstringer:main Jun 27, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant