Closed SivaneshLogandurai closed 4 months ago
v1.7.2 was built with go1.21.11. Looks like it just missed the go1.21.12 release, which was released the same day on 2024-07-02. We can release a new version that uses go1.21.12.
Yes, it was on the same day unfortunately. I will wait for the new version.
@justinvp Can I get an ETA on this ticket?
What happened?
Our scanning jobs have identified a new CVE "CVE-2024-24791" in the pulumi-std v1.7.2. This is an issue with the Go standard library net/http.
Example
CVE scan result
Output of
pulumi about
Using pulumi v3.122.0 and pulumi-std v1.7.2
Additional context
No response
Contributing
Vote on this issue by adding a 👍 reaction. To contribute a fix for this issue, leave a comment (and link to your pull request, if you've opened one already).