Skip to content

Release new version built with Go >= 1.25.7 (CVE-2025-68121) #8

Description

@gifi71

Hi! The pre-built binaries in v0.2.1 are compiled with Go 1.25.4, which is affected by CVE-2025-68121 (unexpected TLS session resumption in crypto/tls).
The fix is available in Go 1.24.13, 1.25.7, and 1.26.0-rc.3.
Could you publish a new release built with a patched Go version?
Detected by Trivy scanning the binary as gobinary in a Docker image. Currently working around this with .trivyignore.

Thanks!

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Fields

    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions