security: upgrade go-getter to v1.8.1 and Go to 1.24 #327
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Summary
Upgrades go-getter from v1.7.9 to v1.8.1 and Go from 1.23 to 1.24 to resolve security vulnerability with AWS SDK v1.
Security Impact
Changes
github.com/hashicorp/go-getterfrom v1.7.9 to v1.8.1github.com/aws/aws-sdk-go v1.44.122Files Changed
go.mod- Dependency and Go version updatesgo.sum- Updated checksums.github/workflows/test.yaml- Added Go 1.24 to CI test matrixTesting
go build ./...)Checklist