From d43a882d5be4b84730e4bed598f1e28a9f9d8d72 Mon Sep 17 00:00:00 2001 From: Ruinan Liu Date: Thu, 19 Feb 2026 15:36:52 -0800 Subject: [PATCH] Pinning to use version 1.24.13 to fix cve --- docker/eno-controller/Dockerfile | 2 ++ docker/eno-reconciler/Dockerfile | 2 ++ 2 files changed, 4 insertions(+) diff --git a/docker/eno-controller/Dockerfile b/docker/eno-controller/Dockerfile index 47e8ba2d..f70f0434 100644 --- a/docker/eno-controller/Dockerfile +++ b/docker/eno-controller/Dockerfile @@ -1,4 +1,6 @@ FROM mcr.microsoft.com/devcontainers/go:1.24 AS builder +# Set GOTOOLCHAIN to ensure the specific version is used during build for fix CVE-2025-68121 +ENV GOTOOLCHAIN=go1.24.13 WORKDIR /app ADD go.mod . diff --git a/docker/eno-reconciler/Dockerfile b/docker/eno-reconciler/Dockerfile index f8c5eca3..5fb7d4d3 100644 --- a/docker/eno-reconciler/Dockerfile +++ b/docker/eno-reconciler/Dockerfile @@ -1,4 +1,6 @@ FROM mcr.microsoft.com/devcontainers/go:1.24 AS builder +# Set GOTOOLCHAIN to ensure the specific version is used during build for fix CVE-2025-68121 +ENV GOTOOLCHAIN=go1.24.13 WORKDIR /app ADD go.mod .