Skip to content

Conversation

@Pive01
Copy link
Collaborator

@Pive01 Pive01 commented Jan 26, 2026

Updated golang dependency to fix CVE-2025-61729

Closes ENG-299

image

@Pive01 Pive01 requested a review from k-a-il January 26, 2026 15:57
@Pive01 Pive01 changed the title chore(Deps): Updated dependencies to remove vulenrabilities chore(Deps): Updated dependencies to remove vulnerabilities Jan 26, 2026
@@ -1,4 +1,4 @@
FROM golang:1.25-alpine AS builder
FROM golang:1.25.6-alpine AS builder
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It is strange that 1.25 is not pointing to the latest 1.25.6 version 🤔 I am looking at dockerhub and it seems that version 1.25 and 1.25.6 have the same digest

Copy link
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think is because we published the last version of the image on October 20, while the fix was live on December 5 ....maybe just re-pushing will also fix the issue 🤔

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yes, this should solve the issue. If the localstack-docker-desktop image is build again, new version of go-1.25-alpine will be fetched during build and the issue must be resolved 👍

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants