Comments (5)
Makes sense. I am using go 1.21.1
Yes you need to upgrade :)
So go.mod only defines the minimum version of Go that's compatible with the repository. Output of govulncheck depends on the version used by the end-user.
Correct (for stdlib vulns).
When do we decide to update it?
When we use a new feature of the Go language that is only available in the latest release, e.g. the stdlib might add a function that we use. Then we need to bump this version number
from minio-go.
Thank you for the clarifications!!
from minio-go.
go.mod
is the minimum Go version. See https://go.dev/doc/modules/gomod-ref#go
That means that a user of minio-go
who compiles it with Go 1.22 (or whatever the latest is) will not be affected by vulnerabilities in the Go standard library of an older version.
from minio-go.
Also FYI:
~/src/minio-go on master ❯ govulncheck -show verbose ./...
Scanning your code and 167 packages across 10 dependent modules for known vulnerabilities...
Fetching vulnerabilities from the database...
Checking the code against the vulnerabilities...
No vulnerabilities found.
~/src/minio-go on master ❯ go version
go version go1.22.4 darwin/arm64
from minio-go.
Makes sense. I am using go 1.21.1
So go.mod only defines the minimum version of Go that's compatible with the repository. Output of govulncheck depends on the version used by the end-user.
Out of curiosity, how do we decide on the minimum Go version for this repository? When do we decide to update it?
from minio-go.
Related Issues (20)
- Parallel upload in PutObject is only selected for os.File, not for other io.ReaderAt instances. Possibly bug? HOT 4
- Add Amazon EKS Pod Identity support HOT 3
- Resize image with minio client HOT 1
- RemoveObject() does not work as i expect! HOT 4
- Service account GCP HOT 1
- Retrieve object metadata on GCS HOT 2
- How to Validate Checksums using MD5 in MinIO with Go SDK for multi-part upload
- Retry attempt http PUTs for 'mc cp' fail with early EOF HOT 2
- PutObject with expires invalid HOT 1
- Does the Minio SDK use multiple connections to saturate the bandwidth? HOT 1
- Sec vul CVE-2022-28948 from pkg/credentials > ini.v1 > stretchr/testify > yaml.v3 HOT 1
- about Access Policy questiong
- Suggestion : We should default to not using s3 dual stack urls and setting the flag as false by default, considering the inability to use vpc private link in this case HOT 2
- how to set or get metadata? HOT 2
- GCP endpoint validation error HOT 1
- How to modify metadata when uploading files in the following way HOT 1
- Localhost driver? HOT 1
- OOM when transfer big size file from minio to another minio HOT 3
- OpenTelemetry Tracing HOT 4
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from minio-go.