Skip to content

Conversation

@developer-guy
Copy link

@developer-guydeveloper-guy commented Apr 21, 2025

There was a CVE reported:

└── 📄 /usr/share/localstack/.venv/lib/python3.12/site-packages/.filesystem/usr/lib/localstack/lambda-runtime/v0.1.32-pre/arm64/var/rapid/init 📦 golang.org/x/net v0.33.0 (go-module) Medium CVE-2025-22872 fixed in 0.38.0 Medium CVE-2025-22872 GHSA-vvgc-356p-c3xw fixed in 0.38.0 

so this PR aims to fix this.

Signed-off-by: Batuhan Apaydin <[email protected]>
@kbsteere
Copy link

@whummer@bentsku could you review these changes?

@alexrashedalexrashed requested a review from dfanglApril 22, 2025 06:56
@developer-guy
Copy link
Author

kindly ping @dfangl

Copy link
Member

@dfangldfangl left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm happy with this, I will pull in upstream changes and update to go 1.24 before releasing this as well!

@dfangldfangl merged commit 10daeb8 into localstack:localstackApr 24, 2025
1 check passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@developer-guy@kbsteere@dfangl