[release-11.6.1] Go: Bump to 1.24.2 (#103523)
* Go: Bump to 1.24.2 It is not likely we are actually affected by the CVEs, but updating proactively is not a bad idea nonetheless. Fixes: CVE-2025-22871 Fixes: https://github.com/grafana/grafana-operator-experience-squad/issues/1311 * CI: Update golangci-lint * feat: update swagger * feat: update swagger * fix: remove enterprise imports
This commit is contained in:
@@ -102,6 +102,7 @@ func decryptCFB(block cipher.Block, payload []byte) ([]byte, error) {
|
||||
payload = payload[saltLength+aes.BlockSize:]
|
||||
payloadDst := make([]byte, len(payload))
|
||||
|
||||
//nolint:staticcheck // SA1019: We won't change this in old versions
|
||||
stream := cipher.NewCFBDecrypter(block, iv)
|
||||
|
||||
// XORKeyStream can work in-place if the two arguments are the same.
|
||||
@@ -136,6 +137,7 @@ func Encrypt(payload []byte, secret string) ([]byte, error) {
|
||||
return nil, err
|
||||
}
|
||||
|
||||
//nolint:staticcheck // SA1019: We won't change this in old versions
|
||||
stream := cipher.NewCFBEncrypter(block, iv)
|
||||
stream.XORKeyStream(ciphertext[saltLength+aes.BlockSize:], payload)
|
||||
|
||||
|
||||
Reference in New Issue
Block a user