Skip to content

fix: upgrade to 1.24.6 to fix race in lib/pq queries #19214

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 1 commit into from
Aug 7, 2025

Conversation

spikecurtis
Copy link
Contributor

@spikecurtis spikecurtis commented Aug 7, 2025

fixes: coder/internal#731

THIS IS A SECURITY FIX

upgrade to go 1.24.6 to avoid golang/go#74831 (CVE-2025-47907)

Also points to a new version of our lib/pq fork that worked around the Go issue, which should restore better performance.

Copy link
Contributor Author

This stack of pull requests is managed by Graphite. Learn more about stacking.

@spikecurtis spikecurtis requested review from Emyrk and johnstcn August 7, 2025 08:43
@spikecurtis spikecurtis marked this pull request as ready for review August 7, 2025 08:43
@spikecurtis spikecurtis merged commit 91780db into main Aug 7, 2025
60 of 64 checks passed
Copy link
Contributor Author

Merge activity

@spikecurtis spikecurtis deleted the spike/go-1.24.6-lib-pq branch August 7, 2025 09:49
@github-actions github-actions bot locked and limited conversation to collaborators Aug 7, 2025
@spikecurtis
Copy link
Contributor Author

/cherry-pick release/2.25

@spikecurtis
Copy link
Contributor Author

/cherry-pick release/2.24

@spikecurtis
Copy link
Contributor Author

/cherry-pick release/2.23

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

flake: data race in sql or pq: runtime.slicecopy()
2 participants
pFad - Phonifier reborn

Pfad - The Proxy pFad of © 2024 Garber Painting. All rights reserved.

Note: This service is not intended for secure transactions such as banking, social media, email, or purchasing. Use at your own risk. We assume no liability whatsoever for broken pages.


Alternative Proxies:

Alternative Proxy

pFad Proxy

pFad v3 Proxy

pFad v4 Proxy