-
Notifications
You must be signed in to change notification settings - Fork 723
Closed
Labels
changelog-ignoreDon't include this issue in the release changelogDon't include this issue in the release changelog
Description
Grype reported multiple installed versions of Go libs however below is the installed ones, so which one is correct?
stdlib go1.21.6 1.23.8, 1.24.2 go-module CVE-2025-22871 Critical < 0.1% (4th) < 0.1
stdlib go1.22.3 1.23.8, 1.24.2 go-module CVE-2025-22871 Critical < 0.1% (4th) < 0.1
stdlib go1.23.4 1.23.8, 1.24.2 go-module CVE-2025-22871 Critical < 0.1% (4th) < 0.1
stdlib go1.24.0 1.23.8, 1.24.2 go-module CVE-2025-22871 Critical < 0.1% (4th) < 0.1
go 1.24.4 1.23.12, 1.24.6 binary CVE-2025-47907 High < 0.1% (5th) < 0.1
# dpkg -l | grep golang
ii golang-1.24-go 1.24.4-1ubuntu1 amd64 Go programming language compiler, linker, compiled stdlib
ii golang-1.24-src 1.24.4-1ubuntu1 all Go programming language - source files
ii golang-go:amd64 2:1.24~2 amd64 Go programming language compiler, linker, compiled stdlib
ii golang-src 2:1.24~2 all Go programming language - source files
Metadata
Metadata
Assignees
Labels
changelog-ignoreDon't include this issue in the release changelogDon't include this issue in the release changelog
Type
Projects
Status
Done