Skip to content
Snippets Groups Projects
  1. Feb 12, 2025
  2. Feb 10, 2025
    • Masashi Honma's avatar
      Bump golang from 1.23.5 to 1.23.6 to fix CVE-2025-22866 (#1800) · fcb6517b
      Masashi Honma authored
      This is the scan result of Trivy.
      
      usr/local/bin/kube-bench (gobinary)
      ===================================
      Total: 1 (UNKNOWN: 1, LOW: 0, MEDIUM: 0, HIGH: 0, CRITICAL: 0)
      
      ┌─────────┬────────────────┬──────────┬────────┬───────────────────┬──────────────────────────────┬────────────────────────────────────────────┐
      │ Library │ Vulnerability  │ Severity │ Status │ Installed Version │        Fixed Version         │                   Title                    │
      ├─────────┼────────────────┼──────────┼────────┼───────────────────┼──────────────────────────────┼────────────────────────────────────────────┤
      │ stdlib  │ CVE-2025-22866 │ UNKNOWN  │ fixed  │ 1.23.5            │ 1.22.12, 1.23.6, 1.24.0-rc.3 │ Timing sidechannel for P-256 on ppc64le in │
      │         │                │          │        │                   │                              │ crypto/internal/nistec                     │
      │         │                │          │        │                   │                              │ https://avd.aquasec.com/nvd/cve-2025-22866
      
       │
      └─────────┴────────────────┴──────────┴────────┴───────────────────┴──────────────────────────────┴────────────────────────────────────────────┘
      
      Signed-off-by: default avatarMasashi Honma <masashi.honma@gmail.com>
      fcb6517b
  3. Feb 04, 2025
  4. Jan 21, 2025
  5. Jan 20, 2025
  6. Jan 16, 2025
  7. Jan 15, 2025
  8. Jan 14, 2025
  9. Jan 13, 2025
  10. Jan 10, 2025
  11. Dec 16, 2024
  12. Dec 12, 2024
  13. Dec 11, 2024
  14. Dec 09, 2024
  15. Dec 06, 2024
  16. Dec 05, 2024
Loading