Skip to content

Conversation

miguelhrocha
Copy link

Description

Hi! We are using dbmate in production, and it got flagged for vulnerabilities due to the latest version being packaged with Go 1.24.2.

I wanted to submit a PR to make a new release of dbmate with the CVE addressed 😄

@miguelhrocha
Copy link
Author

@amacneil any idea why the tests are failing?

@ConProgramming
Copy link

@miguelhrocha fix in another pr here, maybe merge that one into here? #660

@ConProgramming
Copy link

Possibly @dossy can help out

@dossy
Copy link
Collaborator

dossy commented Jul 19, 2025

Yeah, wait for PR #660 to land as it addresses the check failure.

FWIW, I suspect @amacneil might close this PR (and, open a new one himself) since the dbmate release workflow GitHub Action requires the branch to be named following a specific pattern.

@amacneil amacneil mentioned this pull request Jul 23, 2025
@amacneil
Copy link
Owner

hi team, will get a new release out shortly!

amacneil added a commit that referenced this pull request Jul 23, 2025
- Bump version
- Upgrade dependencies

Closes #659
@ConProgramming
Copy link

Beautiful! Thank you

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants