Skip to content

[CVE-2025-68121][CVE-2025-61732] Bump go version to 1.25.7#882

Open
jotamartos wants to merge 1 commit intomongodb:masterfrom
jotamartos:go-1.25.7
Open

[CVE-2025-68121][CVE-2025-61732] Bump go version to 1.25.7#882
jotamartos wants to merge 1 commit intomongodb:masterfrom
jotamartos:go-1.25.7

Conversation

@jotamartos
Copy link
Copy Markdown

Golang 1.25.7 includes two security updates. You can get more information about them in the security advisory.

Signed-off-by: Jota Martos <jota.martos@broadcom.com>
@jotamartos jotamartos requested a review from a team as a code owner February 11, 2026 09:19
@jotamartos jotamartos requested review from jtcovan and removed request for a team February 11, 2026 09:19
@jotamartos
Copy link
Copy Markdown
Author

Sorry, I didn't create a task in Jira as I get the following error

Sorry, you can't sign up to this Jira site at the moment as it's private.

Copy link
Copy Markdown
Collaborator

@jtcovan jtcovan left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@jtcovan jtcovan self-requested a review February 12, 2026 17:07
@JSGInray
Copy link
Copy Markdown

@FGasper are there any updates on this CVE issue?

@cruwe
Copy link
Copy Markdown

cruwe commented Mar 9, 2026

First and foremost, thank you very much for developing mongodb and the corresponding tools.

Would it be possible to merge and release this PR soonish? We are starting to experience OSI-9 problems (company bureaucracy) and we would really like to lose the CVE in the golang stdlibs.

Thnak you very much for your consideration!

@subrata71
Copy link
Copy Markdown

@jotamartos Thanks for the contribution.
@jtcovan Could you please share an approximate ETA for merging this PR? We are tracking the related vulnerability fixes and it would help us plan our dependency updates. Thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants