Skip to content

Update Go to 1.25#245

Merged
SuperQ merged 1 commit intoprometheus-community:masterfrom
proddi:bump-to-1-24
Nov 3, 2025
Merged

Update Go to 1.25#245
SuperQ merged 1 commit intoprometheus-community:masterfrom
proddi:bump-to-1-24

Conversation

@proddi
Copy link
Contributor

@proddi proddi commented Oct 29, 2025

Update Go to fix vulnerabilities

  • Update Go build to 1.25 (required to get fixed dependencies).
  • Update dependencies to fix vulnerabilities:
    $ grype .
    NAME                 INSTALLED  FIXED-IN  TYPE       VULNERABILITY        SEVERITY
    golang.org/x/crypto  v0.32.0    0.35.0    go-module  GHSA-hcg3-q754-cr77  High      
    golang.org/x/net     v0.33.0    0.38.0    go-module  GHSA-vvgc-356p-c3xw  Medium    
    golang.org/x/net     v0.33.0    0.36.0    go-module  GHSA-qxp5-gwg8-xv66  Medium    
    golang.org/x/oauth2  v0.24.0    0.27.0    go-module  GHSA-6v2p-p543-phr9  High
    

@SuperQ
Copy link
Contributor

SuperQ commented Oct 29, 2025

This needs a DCO sign-off. You can use git commit -s --amend to add it.

@proddi proddi changed the title Update Go to 1.24 to fix vulnerabilities in dependencies Update Go to 1.25 to fix vulnerabilities in dependencies Oct 29, 2025
@proddi proddi requested a review from SuperQ October 29, 2025 12:54
@proddi proddi changed the title Update Go to 1.25 to fix vulnerabilities in dependencies Update Go to 1.24 to fix vulnerabilities in dependencies Oct 29, 2025
@proddi proddi requested a review from SuperQ October 29, 2025 15:44
@SuperQ SuperQ changed the title Update Go to 1.24 to fix vulnerabilities in dependencies Update Go to 1.25 Oct 29, 2025
@SuperQ
Copy link
Contributor

SuperQ commented Nov 3, 2025

Fixed up the golangci-lint config in #246

* This fixes vulnerabilities

Signed-off-by: Torsten Sachse <torsten.sachse@sap.com>
@proddi
Copy link
Contributor Author

proddi commented Nov 3, 2025

Fixed up the golangci-lint config in #246

rebased against it

@SuperQ SuperQ merged commit cad22e2 into prometheus-community:master Nov 3, 2025
4 checks passed
@proddi proddi deleted the bump-to-1-24 branch November 3, 2025 13:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants