operator-registry icon indicating copy to clipboard operation
operator-registry copied to clipboard

Update Go to 1.24.10 to fix multiple CVEs (including High severity)

Open ErickRDS opened this issue 1 month ago • 0 comments

Our security scanners are flagging the current opm image because it is built with a vulnerable Go version. The following Go-related CVEs are being reported: CVE-2025-47912, CVE-2025-58183, CVE-2025-58185, CVE-2025-58186, CVE-2025-58188, CVE-2025-58189, CVE-2025-61723, CVE-2025-61724, and CVE-2025-61725. At least two of these are classified as High severity by our scanners, which blocks us from passing internal security checks. We would like to request that opm be rebuilt using Go 1.24.10 (or newer in the 1.24 line), updating the go/toolchain configuration accordingly, and that a new release be published so we can update our deployment and clear these findings.

ErickRDS avatar Nov 21 '25 19:11 ErickRDS