Commit fd113dd
authored
deps(cve-2025-47907): update golang base images from 1.24.4 to 1.24.6 across multiple Dockerfiles (#1824)
# Description
Updated Go Lang version to mitigate cve-2025-47907
CVE-2025-47907 is a vulnerability in the Go programming language's
database/sql package, discovered and disclosed on August 7, 2025. The
vulnerability affects multiple versions of Go, specifically versions
before 1.23.12 and from 1.24.0 before 1.24.6. This security issue was
reported by Spike Curtis from Coder ([Go
Project](https://pkg.go.dev/vuln/GO-2025-3849)).
The issue has been fixed in Go versions 1.23.12 and 1.24.6. Users are
advised to upgrade to these patched versions to mitigate the
vulnerability ([Go
Project](https://groups.google.com/g/golang-announce/c/x5MKroML2yM)).
We are still waiting on hubble to bump their version with 1.24.6 golang
version.
<img width="1134" height="572" alt="image"
src="https://github.com/user-attachments/assets/7d55ec73-41e8-4c8b-9676-c51708d679fa"
/>
source; [CVE-2025-47907 Impact, Exploitability, and Mitigation Steps |
Wiz](https://www.wiz.io/vulnerability-database/cve/cve-2025-47907)
## Checklist
- [x ] I have read the [contributing
documentation](https://retina.sh/docs/Contributing/overview).
- [x ] I signed and signed-off the commits (`git commit -S -s ...`). See
[this
documentation](https://docs.github.com/en/authentication/managing-commit-signature-verification/about-commit-signature-verification)
on signing commits.
- [x ] I have correctly attributed the author(s) of the code.
- [x ] I have tested the changes locally.
- [x ] I have followed the project's style guidelines.
- [x ] I have updated the documentation, if necessary.
- [x ] I have added tests, if applicable.
## Screenshots (if applicable) or Testing Completed
This pull request upgrades the Go toolchain version used across all
Dockerfiles and in the `go.mod` file from 1.24.4 (or 1.24.3 in `go.mod`)
to 1.24.6. This ensures consistency and brings in the latest bug fixes
and security updates from the Go project.
**Go toolchain version upgrade:**
* All Dockerfiles now use
`mcr.microsoft.com/oss/go/microsoft/golang:1.24.6` (or the appropriate
Windows variant) instead of `1.24.4`, updating the image digests and
comments accordingly.
[[1]](diffhunk://#diff-53fad39439c11209d1fd09c9c8dc733647e91161167f7daf14df477b78f06472L1-R2)
[[2]](diffhunk://#diff-df234eb86d676bd9233f232e9dc9af4895969477a6a9ff9161e32621f6ce76d1L5-R6)
[[3]](diffhunk://#diff-49752700516c4cf7846baa53e3fcb9f628bff653b0364de4b273f9b900af954aL1-R2)
[[4]](diffhunk://#diff-f0dd51cf34c442cdab8226a50e290ac00ab8276c9f8681dc4d8375ec07a8b3acL1-R2)
[[5]](diffhunk://#diff-1ca5f5c74f2ae2779bc17c72c3b9e4eea6c410dee21dd74117fef13f7611980cL1-R2)
[[6]](diffhunk://#diff-7a317aaf2c0c39b0de61c4caa9ea7320062bae56d464e644eaeb3cd05e17b184L1-R2)
[[7]](diffhunk://#diff-1e96bef04d487cb2a4483d264828b723c73f33f3d8cd86facfd7b979b555b96cL1-R2)
[[8]](diffhunk://#diff-909d3861ff2ca17f232d98e86c2bcb422c49017732b04357a88210be028f7f17L6-R7)
[[9]](diffhunk://#diff-fb3f33cdd2a5865385222d244e9bdc9a7ebee2756d506f6495f83a5cff42b25aL1-R2)
[[10]](diffhunk://#diff-0e1ebad4bf0d52c96d7d08447f373313b76ccb05384d36736eb6c1476744fb86L1-R2)
[[11]](diffhunk://#diff-bc2ff77ba131a806e5fddea1973783d61fdba4e8a33f307a982dca3b29b3956bL1-R2)
[[12]](diffhunk://#diff-105352849a03a69e1cb5f3d40e843034731e66737f833014a4589a6aeee29646L2-R3)
[[13]](diffhunk://#diff-6a4f3c9e54acfa9ffd27a142ad70e1a7bb68c5d3d454366569fb2f148ac94993L1-R1)
[[14]](diffhunk://#diff-0793df634d5904e90d444dade524fa1764c63179f1b3cca617f241a0e0711331L1-R1)
* The `go.mod` file is updated to specify Go version 1.24.6 instead of
1.24.3.[Copilot is generating a summary...]
## Additional Notes
Add any additional notes or context about the pull request here.
---
Please refer to the [CONTRIBUTING.md](../CONTRIBUTING.md) file for more
information on how to contribute to this project.1 parent 886904c commit fd113dd
File tree
16 files changed
+30
-30
lines changed- cli
- controller
- hack/tools
- kapinger
- toolbox
- operator
- test/image
16 files changed
+30
-30
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | | - | |
2 | | - | |
| 1 | + | |
| 2 | + | |
3 | 3 | | |
4 | 4 | | |
5 | 5 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
2 | 2 | | |
3 | 3 | | |
4 | 4 | | |
5 | | - | |
6 | | - | |
| 5 | + | |
| 6 | + | |
7 | 7 | | |
8 | 8 | | |
9 | 9 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | | - | |
2 | | - | |
| 1 | + | |
| 2 | + | |
3 | 3 | | |
4 | 4 | | |
5 | 5 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | | - | |
2 | | - | |
| 1 | + | |
| 2 | + | |
3 | 3 | | |
4 | 4 | | |
5 | 5 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | | - | |
2 | | - | |
| 1 | + | |
| 2 | + | |
3 | 3 | | |
4 | 4 | | |
5 | 5 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | | - | |
2 | | - | |
| 1 | + | |
| 2 | + | |
3 | 3 | | |
4 | 4 | | |
5 | 5 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | | - | |
2 | | - | |
| 1 | + | |
| 2 | + | |
3 | 3 | | |
4 | 4 | | |
5 | 5 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
3 | 3 | | |
4 | 4 | | |
5 | 5 | | |
6 | | - | |
7 | | - | |
| 6 | + | |
| 7 | + | |
8 | 8 | | |
9 | 9 | | |
10 | 10 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | 2 | | |
3 | | - | |
| 3 | + | |
4 | 4 | | |
5 | 5 | | |
6 | 6 | | |
| |||
458 | 458 | | |
459 | 459 | | |
460 | 460 | | |
461 | | - | |
| 461 | + | |
462 | 462 | | |
463 | 463 | | |
464 | 464 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
663 | 663 | | |
664 | 664 | | |
665 | 665 | | |
666 | | - | |
667 | | - | |
| 666 | + | |
| 667 | + | |
668 | 668 | | |
669 | 669 | | |
670 | 670 | | |
| |||
0 commit comments