Skip to content

Update Go to 1.25.3 and Alpine to 3.21.3 to address security vulnerab…#26

Open
vikram-avesha wants to merge 1 commit intomasterfrom
fix-trivy-scan-issues
Open

Update Go to 1.25.3 and Alpine to 3.21.3 to address security vulnerab…#26
vikram-avesha wants to merge 1 commit intomasterfrom
fix-trivy-scan-issues

Conversation

@vikram-avesha
Copy link
Copy Markdown

🔒 Security: Update Go and Alpine versions to address vulnerabilities

Changes

  • Updated Go from 1.22.51.25.3
  • Updated Alpine from 3.20.13.21.3
  • Updated go.mod directive from go 1.18go 1.25

Impact

  • Addresses 12 Alpine vulnerabilities (including 4 HIGH severity OpenSSL issues)
  • Addresses 22+ Go stdlib HIGH severity vulnerabilities
  • No dependency version changes required

Trivy Scan Results (Before)

  • Alpine: 12 vulnerabilities (8 MEDIUM, 4 HIGH)
  • Go Binary (stdlib 1.22.5): 22 vulnerabilities (16 MEDIUM, 6 HIGH)
  • Multiple CVEs in OpenSSL (libcrypto3, libssl3)
  • Critical Go stdlib issues (CVE-2025-58183, CVE-2025-58186, etc.)

Expected significant vulnerability reduction after this update.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant