From f56405e7457ec30e00f49bcf002120d9839cf62a Mon Sep 17 00:00:00 2001 From: Michael Zalimeni Date: Thu, 9 May 2024 11:11:01 -0400 Subject: [PATCH] security: Upgrade Go to 1.21.10 (#21074) This resolves CVE-2024-24787 and CVE-2024-24788. --- .changelog/21074.txt | 5 +++++ .go-version | 2 +- 2 files changed, 6 insertions(+), 1 deletion(-) create mode 100644 .changelog/21074.txt diff --git a/.changelog/21074.txt b/.changelog/21074.txt new file mode 100644 index 0000000000..9b2bd21f42 --- /dev/null +++ b/.changelog/21074.txt @@ -0,0 +1,5 @@ +```release-note:security +Upgrade Go to use 1.21.10. This addresses CVEs +[CVE-2024-24787](https://nvd.nist.gov/vuln/detail/CVE-2024-24787) and +[CVE-2024-24788](https://nvd.nist.gov/vuln/detail/CVE-2024-24788) +``` diff --git a/.go-version b/.go-version index f124bfa155..ae7bbdf047 100644 --- a/.go-version +++ b/.go-version @@ -1 +1 @@ -1.21.9 +1.21.10