Skip to content

Conversation

sudo-bmitch
Copy link
Contributor

Fixes issue

Describe the change

Routine version bump:

  • Go to v1.23.6
  • ECR helper to latest commit
  • sigstore/cosign to v2.4.2
  • docker/setup-buildx-action to v3.9.0
  • sigstore/cosign-installer to v3.8.0
  • golang.org/x/sys to v0.30.0
  • golang.org/x/term to v0.29.0

The Go update fixes CVE-2025-22866. Details can be found at: https://osv.dev/vulnerability/GO-2025-3447

How to verify it

Changelog text

Please verify and check that the pull request fulfills the following requirements

  • Tests have been added or not applicable
  • Documentation has been added, updated, or not applicable
  • Changes have been rebased to main
  • Multiple commits to the same code have been squashed

- Go to v1.23.6
- ECR helper to latest commit
- sigstore/cosign to v2.4.2
- docker/setup-buildx-action to v3.9.0
- sigstore/cosign-installer to v3.8.0
- golang.org/x/sys to v0.30.0
- golang.org/x/term to v0.29.0

Security: the Go update fixes CVE-2025-22866
Signed-off-by: Brandon Mitchell <git@bmitch.net>
@sudo-bmitch sudo-bmitch merged commit 2dc14ba into regclient:main Feb 9, 2025
5 checks passed
@sudo-bmitch sudo-bmitch deleted the pr-update-20250209 branch February 9, 2025 15:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant