Skip to content

Conversation

davidk-procore
Copy link
Contributor

PR to bump Golang version to 1.24.4 to address CVE-2025-22874. This was already done in #626 but it failed due to EPIPE errors. As such also bumping the codecov-action to the newest 4.x release to avoid that going forward.

fixes #627

Tagging @Fauzyy @alecjacobs5401 as the two most recent committers on this project. Happy for y'all to close this in favor of #626 if desired. Thanks!

@davidk-procore davidk-procore requested a review from a team as a code owner June 25, 2025 21:41
@davidk-procore
Copy link
Contributor Author

@segmentio/cloud-native-foundations hope y'all had a good holiday! Is it possible to get the Golang version bumped and address this vuln? Much thanks!

@davidk-procore davidk-procore changed the title Golang & codecov updates fix: Golang & codecov updates Jul 7, 2025
@davidk-procore davidk-procore changed the title fix: Golang & codecov updates fix: Golang & codecov version updates Jul 7, 2025
Copy link

codecov bot commented Jul 21, 2025

Codecov Report

All modified and coverable lines are covered by tests ✅

Project coverage is 36.43%. Comparing base (17887d6) to head (137834e).
Report is 1 commits behind head on master.

Current head 137834e differs from pull request most recent head f23d6a5

Please upload reports for the commit f23d6a5 to get more accurate results.

Additional details and impacted files
@@           Coverage Diff           @@
##           master     #629   +/-   ##
=======================================
  Coverage   36.43%   36.43%           
=======================================
  Files          29       29           
  Lines        3261     3261           
=======================================
  Hits         1188     1188           
  Misses       1986     1986           
  Partials       87       87           

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@davidk-procore
Copy link
Contributor Author

@prasadkatti thanks for the approval! Looks like I don't have permission to merge. Can you or someone on your team do it? Much thanks!

@Fauzyy Fauzyy merged commit 7c8de43 into segmentio:master Jul 23, 2025
3 checks passed
@davidk-procore davidk-procore deleted the golang-codecov-updates branch July 24, 2025 15:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

CVE-2025-22874, update Go to version 1.24.4
4 participants