From 8698a97b77a8dedcfff48daefa3ebdfcc01b3a28 Mon Sep 17 00:00:00 2001 From: Sebastiaan van Stijn Date: Fri, 14 Dec 2018 00:42:34 +0100 Subject: [PATCH] Bump Golang 1.11.3 (CVE-2018-16875) go1.11.13 (released 2018/12/14) - crypto/x509: CPU denial of service in chain validation golang/go#29233 - cmd/go: directory traversal in "go get" via curly braces in import paths golang/go#29231 - cmd/go: remote command execution during "go get -u" golang/go#29230 See the Go 1.11.3 milestone on the issue tracker for details: https://github.com/golang/go/issues?q=milestone%3AGo1.11.3 Signed-off-by: Sebastiaan van Stijn Upstream-commit: 6b7c093b0de21d574ce120aee891e60187749174 Component: engine --- components/engine/Dockerfile | 2 +- components/engine/Dockerfile.e2e | 2 +- components/engine/Dockerfile.simple | 2 +- components/engine/Dockerfile.windows | 2 +- 4 files changed, 4 insertions(+), 4 deletions(-) diff --git a/components/engine/Dockerfile b/components/engine/Dockerfile index 8337653e193..5d2fc1a54fe 100644 --- a/components/engine/Dockerfile +++ b/components/engine/Dockerfile @@ -24,7 +24,7 @@ # the case. Therefore, you don't have to disable it anymore. # -FROM golang:1.11.2 AS base +FROM golang:1.11.3 AS base # allow replacing httpredir or deb mirror ARG APT_MIRROR=deb.debian.org RUN sed -ri "s/(httpredir|deb).debian.org/$APT_MIRROR/g" /etc/apt/sources.list diff --git a/components/engine/Dockerfile.e2e b/components/engine/Dockerfile.e2e index 5cfb5a1ac76..1afad14c787 100644 --- a/components/engine/Dockerfile.e2e +++ b/components/engine/Dockerfile.e2e @@ -1,5 +1,5 @@ ## Step 1: Build tests -FROM golang:1.11.2-alpine3.7 as builder +FROM golang:1.11.3-alpine3.7 as builder RUN apk --no-cache add \ bash \ diff --git a/components/engine/Dockerfile.simple b/components/engine/Dockerfile.simple index f17c28a0964..2a9675fdae0 100644 --- a/components/engine/Dockerfile.simple +++ b/components/engine/Dockerfile.simple @@ -5,7 +5,7 @@ # This represents the bare minimum required to build and test Docker. -FROM golang:1.11.2-stretch +FROM golang:1.11.3-stretch # allow replacing httpredir or deb mirror ARG APT_MIRROR=deb.debian.org diff --git a/components/engine/Dockerfile.windows b/components/engine/Dockerfile.windows index 8689389b16c..d679461682a 100644 --- a/components/engine/Dockerfile.windows +++ b/components/engine/Dockerfile.windows @@ -161,7 +161,7 @@ SHELL ["powershell", "-Command", "$ErrorActionPreference = 'Stop'; $ProgressPref # Environment variable notes: # - GO_VERSION must be consistent with 'Dockerfile' used by Linux. # - FROM_DOCKERFILE is used for detection of building within a container. -ENV GO_VERSION=1.11.2 ` +ENV GO_VERSION=1.11.3 ` GIT_VERSION=2.11.1 ` GOPATH=C:\go ` FROM_DOCKERFILE=1