Skip to content

Commit 46c0d07

Browse files
Update golang version for telemetry build in sonic-slave-buster to fix (sonic-net#14636)
Update golang version for telemetry build in sonic-slave-jessie to fix CVE-2021-33195, this PR will be merged into 201911 branch finally. #### Why I did it Go before 1.15.13 and 1.16.x before 1.16.5 has functions for DNS lookups that do not validate replies from DNS servers, and thus a return value may contain an unsafe injection (e.g., XSS) that does not conform to the RFC1035 format. Now in 201911 and 202012 branch we're using 1.14.2 ##### Work item tracking - Microsoft ADO **(number only)**:17727291 #### How I did it Bump golang version into 1.15.15 which contains corresponding fix. #### How to verify it unit test to do sanity check.
1 parent 7931abd commit 46c0d07

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

sonic-slave-jessie/Dockerfile.j2

+1-1
Original file line numberDiff line numberDiff line change
@@ -261,7 +261,7 @@ RUN apt-get -y build-dep linux
261261
{%- endif %}
262262

263263
# For gobgp and telemetry build
264-
RUN export VERSION=1.14.2 \
264+
RUN export VERSION=1.15.15 \
265265
{%- if CONFIGURED_ARCH == "armhf" %}
266266
&& wget https://storage.googleapis.com/golang/go$VERSION.linux-armv6l.tar.gz \
267267
&& tar -C /usr/local -xzf go$VERSION.linux-armv6l.tar.gz \

0 commit comments

Comments
 (0)