Skip to content

fix: upgrade to go 1.25 versions for remaining 11 HIGH CVEs - #748

Open
qiluo-msft wants to merge 1 commit into
fix/cve-pr1-dcofrom
fix/cve-pr2-dco
Open

qiluo-msft wants to merge 1 commit into
fix/cve-pr1-dcofrom
fix/cve-pr2-dco

Conversation

@qiluo-msft

Copy link
Copy Markdown
Collaborator

Why I did it

Follow-up to #747. Upgrades from go 1.24-compatible versions to go 1.25-required versions, fixing the remaining 11 HIGH CVEs that were blocked by CodeQL's Go 1.24 toolchain.

How I did it

Package Old (after #747) New CVEs Fixed
google.golang.org/grpc v1.80.0 v1.82.1 GHSA-hrxh-6v49-42gf
golang.org/x/crypto v0.48.0 v0.52.0 CVE-2026-39828, CVE-2026-39829, CVE-2026-39830, CVE-2026-39831, CVE-2026-39832
golang.org/x/net v0.49.0 v0.55.0 CVE-2026-25681, CVE-2026-27136, CVE-2026-33814, CVE-2026-39821
golang.org/x/text v0.34.0 v0.39.0 CVE-2026-56852

Replace directives aligned with go mod tidy selections (glog v1.2.5, x/sys v0.45.0, protobuf v1.36.11).

CodeQL workflow: Added setup-go@v5 with go-version: '1.25' so CodeQL can resolve modules requiring go ≥ 1.25.

Depends on

#747 must be merged first (or rebase onto master after #747 merges).

How to verify it

trivy fs . --severity CRITICAL,HIGH  # 0 CRITICAL, 0 HIGH remaining

Upgrades from go 1.24-compatible versions to go 1.25-required versions,
fixing 11 additional HIGH CVEs:

- google.golang.org/grpc v1.80.0 -> v1.82.1 (GHSA-hrxh-6v49-42gf)
- golang.org/x/crypto v0.48.0 -> v0.52.0 (CVE-2026-39828, 39829, 39830, 39831, 39832)
- golang.org/x/net v0.49.0 -> v0.55.0 (CVE-2026-25681, 2026-27136, 2026-33814, 2026-39821)
- golang.org/x/text v0.34.0 -> v0.39.0 (CVE-2026-56852)

ci: add Go 1.25 setup to CodeQL workflow so CodeQL can resolve modules
requiring go >= 1.25.0 (grpc v1.82.1, x/crypto v0.52.0).

Depends on: #744

Signed-off-by: Qi Luo <qiluo-msft@users.noreply.github.com>
@mssonicbld

Copy link
Copy Markdown
Contributor

/azp run

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
There may be pipelines that require an authorized user to comment /azp run to run.

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
1 pipeline(s) were filtered out due to trigger conditions.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants