golang: Update to 1.18.1
authorJeffery To <[email protected]>
Fri, 15 Apr 2022 15:27:14 +0000 (23:27 +0800)
committerJosef Schlehofer <[email protected]>
Wed, 9 Nov 2022 13:45:54 +0000 (14:45 +0100)
Includes fixes for:
* CVE-2022-24675 - encoding/pem: stack overflow
* CVE-2022-28327 - crypto/elliptic: generic P-256 panic when scalar has
  too many leading zeroes

This also adds -buildvcs=false to omit VCS information in Go programs.

Signed-off-by: Jeffery To <[email protected]>
(cherry picked from commit 8c0477a89525422f633e9693cc1fe6192db785df)

lang/golang/golang-package.mk
lang/golang/golang/Makefile

index 7d0a99dd1cb3c59731ec78d75ee95373ff7f3f92..6b62e5887822652bee256c363996f4d7b2c013d3 100644 (file)
@@ -238,6 +238,7 @@ GO_PKG_CUSTOM_LDFLAGS= \
 
 GO_PKG_INSTALL_ARGS= \
        -v \
+       -buildvcs=false \
        -trimpath \
        -ldflags "all=$(GO_PKG_DEFAULT_LDFLAGS)" \
        $(if $(GO_PKG_DEFAULT_GCFLAGS),-gcflags "all=$(GO_PKG_DEFAULT_GCFLAGS)") \
index 8bbe49cb8259d24cef16f97a17c616ba1f09d7af..8ad218c765294b923af39f3b106076fbdf6292bd 100644 (file)
@@ -8,7 +8,7 @@
 include $(TOPDIR)/rules.mk
 
 GO_VERSION_MAJOR_MINOR:=1.18
-GO_VERSION_PATCH:=
+GO_VERSION_PATCH:=1
 
 PKG_NAME:=golang
 PKG_VERSION:=$(GO_VERSION_MAJOR_MINOR)$(if $(GO_VERSION_PATCH),.$(GO_VERSION_PATCH))
@@ -20,7 +20,7 @@ GO_SOURCE_URLS:=https://dl.google.com/go/ \
 
 PKG_SOURCE:=go$(PKG_VERSION).src.tar.gz
 PKG_SOURCE_URL:=$(GO_SOURCE_URLS)
-PKG_HASH:=38f423db4cc834883f2b52344282fa7a39fbb93650dc62a11fdf0be6409bdad6
+PKG_HASH:=efd43e0f1402e083b73a03d444b7b6576bb4c539ac46208b63a916b69aca4088
 
 PKG_MAINTAINER:=Jeffery To <[email protected]>
 PKG_LICENSE:=BSD-3-Clause