etcd icon indicating copy to clipboard operation
etcd copied to clipboard

Bump Go to 1.25.5 / 1.24.11

Open ivanvc opened this issue 1 month ago • 4 comments

What would you like to be added?

Go 1.25.5 and 1.24.11 were released yesterday; they include fixes in crypto/x509 for CVEs: CVE-2025-61729 and CVE-2025-61727. According to our Dependency management documentation, we want to stay on the latest patch version. This means updating our stable branches to 1.24.11 and main to 1.25.5.

Progress track:

Why is this needed?

To keep our Go version up to date and to address CVEs: CVE-2025-61729 and CVE-2025-61727

ivanvc avatar Dec 03 '25 20:12 ivanvc

cc. @hwdef

ivanvc avatar Dec 03 '25 20:12 ivanvc

I want to do this, thanks!

hwdef avatar Dec 04 '25 01:12 hwdef

/assign @hwdef

ivanvc avatar Dec 04 '25 16:12 ivanvc

Hi @ivanvc , @hwdef , Have we considered mechanisms to automate this process in the past?

ronaldngounou avatar Dec 05 '25 07:12 ronaldngounou

Hi @ivanvc , @hwdef , Have we considered mechanisms to automate this process in the past?

I have a script locally that automates this. Potentially, it can be triggered in an automated way. However, this is one of those tasks that are good for first-time contributors. So, I haven't decided to push forward with automating this more.

ivanvc avatar Dec 14 '25 05:12 ivanvc

Thanks, @hwdef :)

ivanvc avatar Dec 14 '25 05:12 ivanvc