Skip to content

Conversation

@thevilledev
Copy link
Contributor

@thevilledev thevilledev commented May 18, 2025

Description

Updates Go version across all workflows, Dockerfile and go.mod to address an os.Root related security fix.

This functionality is being used by #22936 (merged) and #22956 (draft PR).

For older ArgoCD release branches it seems there's no need to cherry-pick, as they operate on older Go versions than 1.24 (where os.Root was originally introduced).

Checklist

  • Either (a) I've created an enhancement proposal and discussed it with the community, (b) this is a bug fix, or (c) this does not need to be in the release notes.
  • The title of the PR states what changed and the related issues number (used for the release note).
  • The title of the PR conforms to the Toolchain Guide
  • I've included "Closes [ISSUE #]" or "Fixes [ISSUE #]" in the description to automatically close the associated issue.
  • I've updated both the CLI and UI to expose my feature, or I plan to submit a second PR with them.
  • Does this PR require documentation updates?
  • I've updated documentation as required by this PR.
  • I have signed off all my commits as required by DCO
  • I have written unit and/or e2e tests for my change. PRs without these are unlikely to be merged.
  • My build is green (troubleshooting builds).
  • My new feature complies with the feature status guidelines.
  • I have added a brief description of why this PR is necessary and/or what this PR solves.
  • Optional. My organization is added to USERS.md.
  • Optional. For bug fixes, I've indicated what older releases this fix should be cherry-picked into (this may or may not happen depending on risk/complexity).

Updates Go version across all workflows, Dockerfile and go.mod to
address an os.Root related security fix.

Signed-off-by: Ville Vesilehto <[email protected]>
@thevilledev thevilledev requested review from a team as code owners May 18, 2025 08:39
@bunnyshell
Copy link

bunnyshell bot commented May 18, 2025

❌ Preview Environment deleted from Bunnyshell

Available commands (reply to this comment):

  • 🚀 /bns:deploy to deploy the environment

@codecov
Copy link

codecov bot commented May 18, 2025

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 60.03%. Comparing base (0707bff) to head (d5b0c32).
⚠️ Report is 466 commits behind head on master.

Additional details and impacted files
@@            Coverage Diff             @@
##           master   #23026      +/-   ##
==========================================
+ Coverage   60.01%   60.03%   +0.02%     
==========================================
  Files         343      343              
  Lines       57846    57846              
==========================================
+ Hits        34717    34730      +13     
+ Misses      20361    20346      -15     
- Partials     2768     2770       +2     

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

Copy link
Member

@blakepettersson blakepettersson left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@blakepettersson blakepettersson merged commit 90408cb into argoproj:master May 19, 2025
29 checks passed
ranakan19 pushed a commit to ranakan19/argo-cd that referenced this pull request May 20, 2025
Signed-off-by: Ville Vesilehto <[email protected]>
Signed-off-by: Kanika Rana <[email protected]>
olivergondza pushed a commit to olivergondza/argo-cd that referenced this pull request May 20, 2025
Signed-off-by: Ville Vesilehto <[email protected]>
Signed-off-by: Oliver Gondža <[email protected]>
LyhengTep pushed a commit to LyhengTep/argo-cd that referenced this pull request May 24, 2025
tylerrosnett pushed a commit to StateFarmIns/argo-cd that referenced this pull request May 27, 2025
chansuke pushed a commit to chansuke/argo-cd that referenced this pull request Jun 4, 2025
@blakepettersson
Copy link
Member

/cherry-pick release-3.0

@nitishfy
Copy link
Member

nitishfy commented Jun 4, 2025

@thevilledev would you mind manually raising the cherry pick PRs for v2.14 and v3.0?

@thevilledev
Copy link
Contributor Author

@nitishfy sure thing, I'll do that later today!

@thevilledev
Copy link
Contributor Author

thevilledev commented Jun 4, 2025

@blakepettersson and @nitishfy, just realised Go 1.24.4 will be released tomorrow. It includes one private (yet to be disclosed) CVE fix, so upgrading might be a high priority thing tomorrow. Shall I open those 1.24.4 upgrades for all affected branches then instead of 1.24.3?

@blakepettersson
Copy link
Member

@thevilledev I'm totally fine with waiting for that release

dsuhinin pushed a commit to dsuhinin/argo-cd that referenced this pull request Jun 16, 2025
dsuhinin pushed a commit to dsuhinin/argo-cd that referenced this pull request Jun 16, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants