Skip to content

Commit a1154ab

Browse files
authored
Merge pull request #343 from splitio/FME-14742
[FME-14742] Updated to fix some vulnerabilities
2 parents 6051f28 + 70e1de9 commit a1154ab

File tree

10 files changed

+43
-30
lines changed

10 files changed

+43
-30
lines changed

.github/workflows/s3.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -18,14 +18,14 @@ jobs:
1818
runs-on: ubuntu-latest
1919
steps:
2020
- name: Checkout code
21-
uses: actions/checkout@v4
21+
uses: actions/checkout@v6
2222
with:
2323
fetch-depth: 0
2424

2525
- name: Setup Go
26-
uses: actions/setup-go@v5
26+
uses: actions/setup-go@v6
2727
with:
28-
go-version: '1.24.6'
28+
go-version: '1.26.1'
2929

3030
- name: Create build folder
3131
run: mkdir -p build

.github/workflows/test.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -22,14 +22,14 @@ jobs:
2222
- 6379:6379
2323
steps:
2424
- name: Checkout code
25-
uses: actions/checkout@v4
25+
uses: actions/checkout@v6
2626
with:
2727
fetch-depth: 0
2828

2929
- name: Setup Go
30-
uses: actions/setup-go@v5
30+
uses: actions/setup-go@v6
3131
with:
32-
go-version: '1.24.6'
32+
go-version: '1.26.1'
3333

3434
- name: Get version
3535
run: echo "VERSION=$(awk '/^const Version/{gsub(/"/, "", $4); print $4}' splitio/version.go)" >> $GITHUB_ENV

.github/workflows/update-license-year.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -13,7 +13,7 @@ jobs:
1313
runs-on: ubuntu-latest
1414
steps:
1515
- name: Checkout
16-
uses: actions/checkout@v4
16+
uses: actions/checkout@v6
1717
with:
1818
fetch-depth: 0
1919

CHANGES.txt

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,12 @@
1+
5.12.2 (Apr 7, 2026)
2+
- Updated golang image to 1.26.1
3+
- Updated golang.org/x/arch to v0.25.0
4+
- Updated golang.org/x/crypto to v0.49.0
5+
- Updated golang.org/x/net to 0.52.0
6+
- Updated golang.org/x/sync to 0.20.0
7+
- Updated golang.org/x/sys to 0.42.0
8+
- Updated golang.org/x/text to 0.35.0
9+
110
5.12.1 (Feb 19, 2026)
211
- Updated docker images and dependencies for vulnerability fixes.
312

docker/Dockerfile.proxy

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
# Build stage
2-
FROM golang:1.24.13-bookworm AS builder
2+
FROM golang:1.26.1-trixie AS builder
33

44
ARG EXTRA_BUILD_ARGS
55
ARG FIPS_MODE
@@ -20,6 +20,7 @@ RUN bash -c 'if [[ "${FIPS_MODE}" = "enabled" ]]; \
2020
FROM debian:13.3 AS runner
2121

2222
RUN apt update -y
23+
RUN apt upgrade -y
2324
RUN apt install -y bash ca-certificates
2425
RUN groupadd -g 1000 split-proxy
2526
RUN useradd -r -u 1000 -g split-proxy -s /usr/sbin/nologin split-proxy

docker/Dockerfile.synchronizer

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
# Build stage
2-
FROM golang:1.24.13-bookworm AS builder
2+
FROM golang:1.26.1-trixie AS builder
33

44
ARG EXTRA_BUILD_ARGS
55
ARG FIPS_MODE
@@ -21,6 +21,7 @@ RUN bash -c 'if [[ "${FIPS_MODE}" = "enabled" ]]; \
2121
FROM debian:13.3 AS runner
2222

2323
RUN apt update -y
24+
RUN apt upgrade -y
2425
RUN apt install -y bash ca-certificates
2526
RUN groupadd -g 1000 split-synchronizer
2627
RUN useradd -r -u 1000 -g split-synchronizer -s /usr/sbin/nologin split-synchronizer

go.mod

Lines changed: 7 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
module github.com/splitio/split-synchronizer/v5
22

3-
go 1.24.13
3+
go 1.26.1
44

55
require (
66
github.com/gin-contrib/cors v1.6.0
@@ -44,12 +44,12 @@ require (
4444
github.com/stretchr/objx v0.5.2 // indirect
4545
github.com/twitchyliquid64/golang-asm v0.15.1 // indirect
4646
github.com/ugorji/go/codec v1.3.0 // indirect
47-
golang.org/x/arch v0.24.0 // indirect
48-
golang.org/x/crypto v0.48.0 // indirect
49-
golang.org/x/net v0.50.0 // indirect
50-
golang.org/x/sync v0.19.0 // indirect
51-
golang.org/x/sys v0.41.0 // indirect
52-
golang.org/x/text v0.34.0 // indirect
47+
golang.org/x/arch v0.25.0 // indirect
48+
golang.org/x/crypto v0.49.0 // indirect
49+
golang.org/x/net v0.52.0 // indirect
50+
golang.org/x/sync v0.20.0 // indirect
51+
golang.org/x/sys v0.42.0 // indirect
52+
golang.org/x/text v0.35.0 // indirect
5353
google.golang.org/protobuf v1.36.8 // indirect
5454
gopkg.in/yaml.v3 v3.0.1 // indirect
5555
)

go.sum

Lines changed: 14 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -97,22 +97,24 @@ github.com/ugorji/go/codec v1.3.0 h1:Qd2W2sQawAfG8XSvzwhBeoGq71zXOC/Q1E9y/wUcsUA
9797
github.com/ugorji/go/codec v1.3.0/go.mod h1:pRBVtBSKl77K30Bv8R2P+cLSGaTtex6fsA2Wjqmfxj4=
9898
go.etcd.io/bbolt v1.3.6 h1:/ecaJf0sk1l4l6V4awd65v2C3ILy7MSj+s/x1ADCIMU=
9999
go.etcd.io/bbolt v1.3.6/go.mod h1:qXsaaIqmgQH0T+OPdb99Bf+PKfBBQVAdyD6TY9G8XM4=
100-
golang.org/x/arch v0.24.0 h1:qlJ3M9upxvFfwRM51tTg3Yl+8CP9vCC1E7vlFpgv99Y=
101-
golang.org/x/arch v0.24.0/go.mod h1:dNHoOeKiyja7GTvF9NJS1l3Z2yntpQNzgrjh1cU103A=
102-
golang.org/x/crypto v0.48.0 h1:/VRzVqiRSggnhY7gNRxPauEQ5Drw9haKdM0jqfcCFts=
103-
golang.org/x/crypto v0.48.0/go.mod h1:r0kV5h3qnFPlQnBSrULhlsRfryS2pmewsg+XfMgkVos=
100+
golang.org/x/arch v0.25.0 h1:qnk6Ksugpi5Bz32947rkUgDt9/s5qvqDPl/gBKdMJLE=
101+
golang.org/x/arch v0.25.0/go.mod h1:0X+GdSIP+kL5wPmpK7sdkEVTt2XoYP0cSjQSbZBwOi8=
102+
golang.org/x/crypto v0.49.0 h1:+Ng2ULVvLHnJ/ZFEq4KdcDd/cfjrrjjNSXNzxg0Y4U4=
103+
golang.org/x/crypto v0.49.0/go.mod h1:ErX4dUh2UM+CFYiXZRTcMpEcN8b/1gxEuv3nODoYtCA=
104104
golang.org/x/exp v0.0.0-20231006140011-7918f672742d h1:jtJma62tbqLibJ5sFQz8bKtEM8rJBtfilJ2qTU199MI=
105105
golang.org/x/exp v0.0.0-20231006140011-7918f672742d/go.mod h1:ldy0pHrwJyGW56pPQzzkH36rKxoZW1tw7ZJpeKx+hdo=
106-
golang.org/x/net v0.50.0 h1:ucWh9eiCGyDR3vtzso0WMQinm2Dnt8cFMuQa9K33J60=
107-
golang.org/x/net v0.50.0/go.mod h1:UgoSli3F/pBgdJBHCTc+tp3gmrU4XswgGRgtnwWTfyM=
108-
golang.org/x/sync v0.19.0 h1:vV+1eWNmZ5geRlYjzm2adRgW2/mcpevXNg50YZtPCE4=
109-
golang.org/x/sync v0.19.0/go.mod h1:9KTHXmSnoGruLpwFjVSX0lNNA75CykiMECbovNTZqGI=
106+
golang.org/x/net v0.51.0 h1:94R/GTO7mt3/4wIKpcR5gkGmRLOuE/2hNGeWq/GBIFo=
107+
golang.org/x/net v0.51.0/go.mod h1:aamm+2QF5ogm02fjy5Bb7CQ0WMt1/WVM7FtyaTLlA9Y=
108+
golang.org/x/net v0.52.0 h1:He/TN1l0e4mmR3QqHMT2Xab3Aj3L9qjbhRm78/6jrW0=
109+
golang.org/x/net v0.52.0/go.mod h1:R1MAz7uMZxVMualyPXb+VaqGSa3LIaUqk0eEt3w36Sw=
110+
golang.org/x/sync v0.20.0 h1:e0PTpb7pjO8GAtTs2dQ6jYa5BWYlMuX047Dco/pItO4=
111+
golang.org/x/sync v0.20.0/go.mod h1:9xrNwdLfx4jkKbNva9FpL6vEN7evnE43NNNJQ2LF3+0=
110112
golang.org/x/sys v0.0.0-20200923182605-d9f96fdee20d/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs=
111113
golang.org/x/sys v0.6.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
112-
golang.org/x/sys v0.41.0 h1:Ivj+2Cp/ylzLiEU89QhWblYnOE9zerudt9Ftecq2C6k=
113-
golang.org/x/sys v0.41.0/go.mod h1:OgkHotnGiDImocRcuBABYBEXf8A9a87e/uXjp9XT3ks=
114-
golang.org/x/text v0.34.0 h1:oL/Qq0Kdaqxa1KbNeMKwQq0reLCCaFtqu2eNuSeNHbk=
115-
golang.org/x/text v0.34.0/go.mod h1:homfLqTYRFyVYemLBFl5GgL/DWEiH5wcsQ5gSh1yziA=
114+
golang.org/x/sys v0.42.0 h1:omrd2nAlyT5ESRdCLYdm3+fMfNFE/+Rf4bDIQImRJeo=
115+
golang.org/x/sys v0.42.0/go.mod h1:4GL1E5IUh+htKOUEOaiffhrAeqysfVGipDYzABqnCmw=
116+
golang.org/x/text v0.35.0 h1:JOVx6vVDFokkpaq1AEptVzLTpDe9KGpj5tR4/X+ybL8=
117+
golang.org/x/text v0.35.0/go.mod h1:khi/HExzZJ2pGnjenulevKNX1W67CUy0AsXcNubPGCA=
116118
google.golang.org/protobuf v1.36.8 h1:xHScyCOEuuwZEc6UtSOvPbAT4zRh0xcNRYekJwfqyMc=
117119
google.golang.org/protobuf v1.36.8/go.mod h1:fuxRtAxBytpl4zzqUh6/eyUujkJdNiuEkXntxiD/uRU=
118120
gopkg.in/check.v1 v0.0.0-20161208181325-20d25e280405/go.mod h1:Co6ibVJAznAaIkqp8huTwlJQCZ016jof/cbN4VW5Yz0=

splitio/version.go

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,4 +2,4 @@
22
package splitio
33

44
// Version is the version of this Agent
5-
const Version = "5.12.1"
5+
const Version = "5.12.2"

windows/Makefile

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ BUILD_FOLDER := $(CURRENT_PATH)/build
77

88

99
GO := $(BIN_FOLDER)/go
10-
ASSET ?= go1.24.linux-amd64.tar.gz
10+
ASSET ?= go1.26.linux-amd64.tar.gz
1111
SOURCES := $(shell find $(PARENT_PATH) -path $(dirname $(pwd))/windows -prune -o -name "*.go" -print) \
1212
$(PARENT_PATH)/go.mod \
1313
$(PARENT_PATH)/go.sum

0 commit comments

Comments
 (0)