From b71651c1b7ab2022216b98d16280210383563c80 Mon Sep 17 00:00:00 2001 From: Sebastiaan van Stijn Date: Fri, 14 Dec 2018 00:42:34 +0100 Subject: [PATCH] Bump Golang 1.11.3 (CVE-2018-16875) go1.11.13 (released 2018/12/14) - crypto/x509: CPU denial of service in chain validation golang/go#29233 - cmd/go: directory traversal in "go get" via curly braces in import paths golang/go#29231 - cmd/go: remote command execution during "go get -u" golang/go#29230 See the Go 1.11.3 milestone on the issue tracker for details: https://github.com/golang/go/issues?q=milestone%3AGo1.11.3 Signed-off-by: Sebastiaan van Stijn (cherry picked from commit 6b7c093b0de21d574ce120aee891e60187749174) Signed-off-by: Sebastiaan van Stijn Upstream-commit: 19d37c9a337e82e0e8ce0ff28271739e8ec78e83 Component: engine --- components/engine/Dockerfile | 2 +- components/engine/Dockerfile.e2e | 2 +- components/engine/Dockerfile.simple | 2 +- components/engine/Dockerfile.windows | 2 +- 4 files changed, 4 insertions(+), 4 deletions(-) diff --git a/components/engine/Dockerfile b/components/engine/Dockerfile index 147e469ebc..42928e2bc8 100644 --- a/components/engine/Dockerfile +++ b/components/engine/Dockerfile @@ -24,7 +24,7 @@ # the case. Therefore, you don't have to disable it anymore. # -FROM golang:1.11.2 AS base +FROM golang:1.11.3 AS base # allow replacing httpredir or deb mirror ARG APT_MIRROR=deb.debian.org RUN sed -ri "s/(httpredir|deb).debian.org/$APT_MIRROR/g" /etc/apt/sources.list diff --git a/components/engine/Dockerfile.e2e b/components/engine/Dockerfile.e2e index 6e7d5e3124..72e8505d53 100644 --- a/components/engine/Dockerfile.e2e +++ b/components/engine/Dockerfile.e2e @@ -1,5 +1,5 @@ ## Step 1: Build tests -FROM golang:1.11.2-alpine3.7 as builder +FROM golang:1.11.3-alpine3.7 as builder RUN apk add --update \ bash \ diff --git a/components/engine/Dockerfile.simple b/components/engine/Dockerfile.simple index f17c28a096..2a9675fdae 100644 --- a/components/engine/Dockerfile.simple +++ b/components/engine/Dockerfile.simple @@ -5,7 +5,7 @@ # This represents the bare minimum required to build and test Docker. -FROM golang:1.11.2-stretch +FROM golang:1.11.3-stretch # allow replacing httpredir or deb mirror ARG APT_MIRROR=deb.debian.org diff --git a/components/engine/Dockerfile.windows b/components/engine/Dockerfile.windows index 8689389b16..d679461682 100644 --- a/components/engine/Dockerfile.windows +++ b/components/engine/Dockerfile.windows @@ -161,7 +161,7 @@ SHELL ["powershell", "-Command", "$ErrorActionPreference = 'Stop'; $ProgressPref # Environment variable notes: # - GO_VERSION must be consistent with 'Dockerfile' used by Linux. # - FROM_DOCKERFILE is used for detection of building within a container. -ENV GO_VERSION=1.11.2 ` +ENV GO_VERSION=1.11.3 ` GIT_VERSION=2.11.1 ` GOPATH=C:\go ` FROM_DOCKERFILE=1