A maintenance release postpones removal of one flag and reverses another flag's deprecation. It also includes dependency and toolchain updates addressing named security advisories.
Action needed (2)
securityhighThe
gotoolchain, updated to 1.24.13Binaries are compiled using
go 1.. The toolchain update addresses CVE-2025-61726, CVE-2025-61731, CVE-2025-61732, GHSA-8jvr-vh7g-f8gx, GHSA-gm9r-q53w-2gh4, and GHSA-xvqr-69v8-f3gv.24. 13 securitymediumThe
golang.dependency, updated to 0.45.0org/x/crypto golang.is updated to 0.45.0 to address CVE-2025-47914 and CVE-2025-58181.org/x/crypto
Plan ahead (1)
deprecatedThe
--max-snapshotsflag, removal postponedremoval planned in v3.8Applies if you use
--max-snapshots.