[release-11.4.4] Go: Bump to 1.24.2 (#103527)

* Go: Bump to 1.24.2

It is not likely we are actually affected by the CVEs, but updating proactively is not a bad idea nonetheless.

Fixes: CVE-2025-22871
Fixes: https://github.com/grafana/grafana-operator-experience-squad/issues/1311

* CI: Update golangci-lint
This commit is contained in:
Mariell Hoversholm
2025-04-08 17:24:40 +02:00
committed by GitHub
parent ac5703b7fc
commit ef39d1ec35
33 changed files with 263 additions and 141 deletions
@@ -38,6 +38,7 @@ func (c aesCfbCipher) Encrypt(_ context.Context, payload []byte, secret string)
return nil, err
}
//nolint:staticcheck // SA1019: We're not changing away from CFB in older versions
stream := cipher.NewCFBEncrypter(block, iv)
stream.XORKeyStream(ciphertext[encryption.SaltLength+aes.BlockSize:], payload)
@@ -59,6 +59,7 @@ func decryptCFB(block cipher.Block, payload []byte) ([]byte, error) {
payload = payload[encryption.SaltLength+aes.BlockSize:]
payloadDst := make([]byte, len(payload))
//nolint:staticcheck // SA1019: We're not changing away from CFB in older versions
stream := cipher.NewCFBDecrypter(block, iv)
// XORKeyStream can work in-place if the two arguments are the same.