8000 v5: Bump Go and dependencies by pjbgf · Pull Request #1436 · go-git/go-git · GitHub
[go: up one dir, main page]
More Web Proxy on the site http://driver.im/
Skip to content
Dismiss alert

v5: Bump Go and dependencies #1436

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 2 commits into from
Feb 27, 2025
Merged

v5: Bump Go and dependencies #1436

merged 2 commits into from
Feb 27, 2025

Conversation

pjbgf
Copy link
Member
@pjbgf pjbgf commented Feb 26, 2025

Bump Go and dependencies to mitigate GO-2025-3487.

This violates go-git's support for last 3 stable Go versions. Given that v5 is in maintainence mode, users that must be on Go 1.22 can wait to bump to a new release, while we can still provide a fix for users that don't have that requirement.

Signed-off-by: Paulo Gomes <pjbgf@linux.com>
Bumps overall dependencies for the v5 release. The x/crypto dependency
requires toolchain above go1.22, which violates the current support
for last 3 stable Go versions.

Given that this is required to mitigate GO-2025-3487, we are going
ahead with this change. Users that must be in older versions of Go
can wait to bump if they so wish.

Signed-off-by: Paulo Gomes <pjbgf@linux.com>
@pjbgf pjbgf merged commit 863c621 into go-git:releases/v5.x Feb 27, 2025
12 of 13 checks passed
@pjbgf pjbgf deleted the v5-bumps branch February 27, 2025 13:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None ye 42B8 t
Development

Successfully merging this pull request may close these issues.

2 participants
0