mirror of https://github.com/hashicorp/consul
Browse Source
Update Go version to 1.20.6 This resolves [CVE-2023-29406] (https://nvd.nist.gov/vuln/detail/CVE-2023-29406) for uses of the `net/http` standard library. Note that until the follow-up to #18124 is done, the version of Go used in those impacted tests will need to remain on 1.20.5.pull/18197/head
Michael Zalimeni
1 year ago
committed by
GitHub
3 changed files with 17 additions and 12 deletions
@ -0,0 +1,5 @@
|
||||
```release-note:security |
||||
Upgrade to use Go 1.20.6. |
||||
This resolves [CVE-2023-29406](https://github.com/advisories/GHSA-f8f7-69v5-w4vx)(`net/http`) for uses of the standard library. |
||||
A separate change updates dependencies on `golang.org/x/net` to use `0.12.0`. |
||||
``` |
Loading…
Reference in new issue