basecamp / thruster

MIT License
912 stars 31 forks source link

Update Go version to address vulnerabilities (CVE-2024-34158, CVE-2024-34156, CVE-2022-30635) #45

Closed neumayr closed 1 week ago

neumayr commented 1 month ago

👋 Hi Basecamp team, Hey @kevinmcconnell

I hope you're doing well! I'm opening this issue to bring attention to three high-severity vulnerabilities (CVE-2024-34158, CVE-2024-34156, and CVE-2022-30635 [2]) present in the Go standard library in the current version 1.22.1, which is used in this repository. These vulnerabilities have been addressed in Go version 1.23.1. [1]

Would it be possible to update the Go version used in this project to ensure it remains secure?

Thanks for your time and consideration. Keep up the great work! 🤩

Best regards, Matt ✌️🌻

kevinmcconnell commented 1 month ago

Thanks @neumayr, I’ll get an update released shortly 👍