Skip to content

Conversation

adrianosela
Copy link
Contributor

@adrianosela adrianosela commented Jun 5, 2025

[CVE-2025-22871] Bump Module's Go Toolchain to 1.24.3

Bumping to patch for a CVE in the Go std lib: https://nvd.nist.gov/vuln/detail/CVE-2025-22871

Note: Overrides (or requires) #647

@adrianosela
Copy link
Contributor Author

Hey @amacneil -- any chance we could get this in? (merging #652 before it).

@dossy
Copy link
Collaborator

dossy commented Jun 20, 2025

What is the urgency? This only affects Go programs that use a net/http server, which dbmate does not do, and therefore is not at risk/is not directly affected by this issue.

Am I misunderstanding the issue? GHSA-g9pc-8g42-g6vq

@adrianosela
Copy link
Contributor Author

My understanding of the issue is exactly the same @dossy. You are correct that it doesnt apply to dbmate.

It’s mostly because anyone who has a dbmate binary in a server or container in an org with scanning requirements has to go and add an exception for that CVE for dbmate in their scanning system (and write that it doesnt apply because dbmate doesnt serve http).

no urgency, just a nice to have.

@dossy dossy merged commit 6f864cf into amacneil:main Jun 20, 2025
10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants