prometheus / pushgateway

Push acceptor for ephemeral and batch jobs.

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Current release uses go 1.21.1 which has a number of CVEs

yucombinator opened this issue · comments

Bug Report

The latest v1.6.1 release has a number of CVEs due to the Go version that was used to build them:

As pushgateway is built with Go 1.21.1. Can we update to 1.21.5 or above to resolve thes vulnerabilities?

we asked the same: #614. still no answer, looks like master is green from a vulnerability point of view, but was never released.

Yeah, sorry for lagging behind with releases. I'll try to cut one tomorrow.