package/go: security bump to version 1.12.10
authorPeter Korsgaard <peter@korsgaard.com>
Tue, 1 Oct 2019 18:19:26 +0000 (20:19 +0200)
committerPeter Korsgaard <peter@korsgaard.com>
Wed, 2 Oct 2019 06:07:49 +0000 (08:07 +0200)
Fixes the following security vulnerabilities:

- CVE-2019-16276: Go before 1.12.10 and 1.13.x before 1.13.1 allow HTTP
  Request Smuggling.
  https://github.com/golang/go/issues/34540

>From the release notes:

go1.12.10 (released 2019/09/25) includes security fixes to the net/http and
net/textproto packages

Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
package/go/go.hash
package/go/go.mk

index a4820ee67a88d4f2695ccfe6536c9b72604f7dbf..8dfcff7a735045f417877ffb0eb653dab02358ac 100644 (file)
@@ -1,3 +1,3 @@
 # From https://golang.org/dl/
-sha256 ab0e56ed9c4732a653ed22e232652709afbf573e710f56a07f7fdeca578d62fc  go1.12.9.src.tar.gz
+sha256 f56e48fce80646d3c94dcf36d3e3f490f6d541a92070ad409b87b6bbb9da3954  go1.12.10.src.tar.gz
 sha256 2d36597f7117c38b006835ae7f537487207d8ec407aa9d9980794b2030cbc067  LICENSE
index 9b7263a49a51effc01f66b0e6a001daf55a91843..f8727850b52723d269672cda41eb31e915d9f028 100644 (file)
@@ -4,7 +4,7 @@
 #
 ################################################################################
 
-GO_VERSION = 1.12.9
+GO_VERSION = 1.12.10
 GO_SITE = https://storage.googleapis.com/golang
 GO_SOURCE = go$(GO_VERSION).src.tar.gz