Skip to content

Release binary built with outdated Go toolchain #665

Description

@mkhoroshev

问题描述

I ran Trivy against the cfst_linux_amd64 v2.3.5 binary and found 22 stdlib CVEs, including CVE-2025-68121 (CRITICAL, crypto/tls certificate validation), fixed in Go 1.24.13/1.25.7/1.26.0-rc.3. Buildinfo shows it was compiled with go1.24.5.

I know an older toolchain (v1.20) is kept intentionally for legacy-OS builds — this is about the main Linux release specifically. Would a rebuild with a newer 1.24.x+ point release be feasible?

Thanks for the project!

trivy.md

软件版本

v2.3.5

附加截图

No response

Metadata

Metadata

Assignees

No one assigned

    Labels

    反馈问题某些功能失效 或 没有达到预期

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions