danielqsj / kafka_exporter

Kafka exporter for Prometheus
Apache License 2.0
2.18k stars 610 forks source link

Update Go 1.17.1 to a higher version to remove critical CVEs #316

Closed kerstinmaier closed 2 years ago

kerstinmaier commented 2 years ago

The latest Tag 1.4.2 comes with Go 1.17.1 which results in some critical findings in our security scan, namely https://nvd.nist.gov/vuln/detail/CVE-2021-38297 and https://nvd.nist.gov/vuln/detail/cve-2022-23806

Are there plans to make a new release to update to a newer Go version?

danielqsj commented 2 years ago

Already updated to 1.19