-
Wed Jun 25 2025 Alex Burmashev <alexander.burmashev@oracle.com> - 1.23.7-1
- Update to 1.23.7
- golang: crypto/x509: crypto/x509: usage of IPv6 zone IDs can bypass URI name constraints (CVE-2024-45341)
- golang: net/http: net/http: sensitive headers incorrectly sent after cross-domain redirect (CVE-2024-45336)
- crypto/internal/nistec: golang: Timing sidechannel for P-256 on ppc64le in crypto/internal/nistec (CVE-2025-22866)
-
Fri Nov 29 2024 Alejandro Sáez <asm@redhat.com> - 1.23.1-4
- Remove bundled boringcrypto blob
-
Tue Oct 29 2024 Troy Dawson <tdawson@redhat.com> - 1.23.1-3
- Bump release for October 2024 mass rebuild:
-
Wed Sep 25 2024 Derek Parker <deparker@redhat.com> - 1.23.1-2
- Update baserelease
-
Tue Sep 24 2024 Derek Parker <deparker@redhat.com> - 1.23.1-1
- Rebase to 1.23.1
-
Thu Aug 29 2024 Archana <aravinda@redhat.com> - 1.22.5-3
- Include fix that loads Openssl only in FIPS mode - Resolves: RHEL-52486
-
Tue Jul 16 2024 Alejandro Sáez <asm@redhat.com> - 1.22.5-2
- Default to ld.bfd on ARM64
-
Thu Jul 11 2024 Archana <aravinda@redhat.com> - 1.22.5-1
- Rebase to Go1.22.5 to address CVE-2024-24791 - Resolves: RHEL-46971
-
Mon Jun 24 2024 Troy Dawson <tdawson@redhat.com> - 1.22.4-2
- Bump release for June 2024 mass rebuild
-
Thu Jun 06 2024 Archana <aravinda@redhat.com> - 1.22.4-1
- Rebase to Go1.22.4 - Resolves: RHEL-40155