This addresses CVE-2021-34558: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-34558
go1.16.6 (released 2021-07-12) includes a security fix to the crypto/tls package,
as well as bug fixes to the compiler, and the net and net/http packages. See the
Go 1.16.6 milestone on the issue tracker for details:
https://github.com/golang/go/issues?q=milestone%3AGo1.16.6+label%3ACherryPickApproved
Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
(cherry picked from commit fe6f1a4067e15f99adceaa5a1a305103ca09d3f6)
Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
| ... | ... |
@@ -3,7 +3,7 @@ |
| 3 | 3 |
ARG CROSS="false" |
| 4 | 4 |
ARG SYSTEMD="false" |
| 5 | 5 |
# IMPORTANT: When updating this please note that stdlib archive/tar pkg is vendored |
| 6 |
-ARG GO_VERSION=1.16.5 |
|
| 6 |
+ARG GO_VERSION=1.16.6 |
|
| 7 | 7 |
ARG DEBIAN_FRONTEND=noninteractive |
| 8 | 8 |
ARG VPNKIT_VERSION=0.5.0 |
| 9 | 9 |
ARG DOCKER_BUILDTAGS="apparmor seccomp" |
| ... | ... |
@@ -165,7 +165,7 @@ FROM microsoft/windowsservercore |
| 165 | 165 |
# Use PowerShell as the default shell |
| 166 | 166 |
SHELL ["powershell", "-Command", "$ErrorActionPreference = 'Stop'; $ProgressPreference = 'SilentlyContinue';"] |
| 167 | 167 |
|
| 168 |
-ARG GO_VERSION=1.16.5 |
|
| 168 |
+ARG GO_VERSION=1.16.6 |
|
| 169 | 169 |
ARG GOTESTSUM_COMMIT=v0.5.3 |
| 170 | 170 |
|
| 171 | 171 |
# Environment variable notes: |