Skip to content

bug: Update to Go 1.24.4 to resolve multiple CVEs #1660

@seanorama

Description

@seanorama

Describe the issue

Please update to Go 1.24.4 to resolve multiple CVEs. This would also fix #1608.

To Reproduce

Scan with grype, trivy or other CVE scanner:

$ grype ghcr.io/fluent/fluent-operator/fluent-operator:v3.4.0

NAME    INSTALLED  FIXED IN         TYPE       VULNERABILITY   SEVERITY  EPSS           RISK
stdlib  go1.24.1   1.23.10, 1.24.4  go-module  CVE-2025-4673   Medium    < 0.1% (12th)  < 0.1
stdlib  go1.24.1   1.23.8, 1.24.2   go-module  CVE-2025-22871  Critical  < 0.1% (4th)   < 0.1
stdlib  go1.24.1   1.24.4           go-module  CVE-2025-22874  High      < 0.1% (1st)   < 0.1

Expected behavior

Image updated to go 1.24.4

Your Environment

- Fluent Operator version:
- Container Runtime:
- Fluent Operator version: 3.4.0
- Container Runtime: n/a
- Operating system: n/a
- Kernel version: n/a

How did you install fluent operator?

n/a

Additional context

n/a

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions