问题描述
I ran Trivy against the cfst_linux_amd64 v2.3.5 binary and found 22 stdlib CVEs, including CVE-2025-68121 (CRITICAL, crypto/tls certificate validation), fixed in Go 1.24.13/1.25.7/1.26.0-rc.3. Buildinfo shows it was compiled with go1.24.5.
I know an older toolchain (v1.20) is kept intentionally for legacy-OS builds — this is about the main Linux release specifically. Would a rebuild with a newer 1.24.x+ point release be feasible?
Thanks for the project!
trivy.md
软件版本
v2.3.5
附加截图
No response
问题描述
I ran Trivy against the cfst_linux_amd64 v2.3.5 binary and found 22 stdlib CVEs, including CVE-2025-68121 (CRITICAL, crypto/tls certificate validation), fixed in Go 1.24.13/1.25.7/1.26.0-rc.3. Buildinfo shows it was compiled with go1.24.5.
I know an older toolchain (v1.20) is kept intentionally for legacy-OS builds — this is about the main Linux release specifically. Would a rebuild with a newer 1.24.x+ point release be feasible?
Thanks for the project!
trivy.md
软件版本
v2.3.5
附加截图
No response