Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

require golang 1.18 for KD build #628

Closed
joel-bluedata opened this issue Aug 17, 2022 · 0 comments
Closed

require golang 1.18 for KD build #628

joel-bluedata opened this issue Aug 17, 2022 · 0 comments

Comments

@joel-bluedata
Copy link
Member

This will put some CVEs in our rearview mirror.

JFrog scan of 0.10.1 image: 4 critical, 15 high
JFrog scan of master branch build using golang 1.18.5: 1 critical, 8 high

The remaining critical is CVE-2022-1996 from emicklei/go-restful ... we could try to force an update on that package or we might be required to finally move to a more recent version of operator SDK. I'm not super exercised about that one though because as described in emicklei/go-restful#489 it does not apply to KD.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant