-
Notifications
You must be signed in to change notification settings - Fork 14
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Bumping Golang to 1.22 and all the dependencies to fix CVE-2024-24790 #86
base: main
Are you sure you want to change the base?
Conversation
Thanks for your pull request! It looks like this may be your first contribution to a Google open source project. Before we can look at your pull request, you'll need to sign a Contributor License Agreement (CLA). View this failed invocation of the CLA check for more information. For the most up to date status, view the checks section at the bottom of the pull request. |
👋🏻 hey @xiangshen-dk, nice to meet you, I am mentioning you as manager of the latest releases of the library. Can you take a look at this PR? Thanks a lot! |
@xiangshen-dk |
Introduction
Hello there, I am Luis Redondo, I work as a Data Engineer in Cabify and we are heavy users of Google Cloud Platform in "all things Data" and also use Prometheus + Grafana for our observability stack.
Problem
We, as a company, host our own Grafana instances, and we wanted to install the
cloud-logging-data-source-plugin
to show logs of a series of running services. We have static checks for Security violations, and adding the plugin started to throw these errors:It is basically repeated occurrences of the CVE-2024-24790.
Proposed solution
Since the vulnerability seems to have been fixed starting with Golang 1.22.4, I've updated the Golang version and all the Go dependencies. Additionally, since I wanted to generate a test version of the plugin and test it in our private Grafana instance, I've had to also update the node.js libraries, regenerate the yarn.lock file and update several Github Actions used in the release process.
Hope the review process doesn't get too muddy 🙏🏻