<@alexsaezm:fedora.im>
18:00:59
!startmeeting Go SIG meeting
<@meetbot:fedora.im>
18:01:00
Meeting started at 2026-08-24 18:00:59 UTC
<@meetbot:fedora.im>
18:01:01
The Meeting name is 'Go SIG meeting'
<@alexsaezm:fedora.im>
18:01:04
<@alexsaezm:fedora.im>
18:01:04
!topic Roll Call
<@alexsaezm:fedora.im>
18:01:09
<@alexsaezm:fedora.im>
18:01:09
Hi everyone! As always we'll wait ~5 minutes for everyone to join.
<@buckaroogeek:fedora.im>
18:01:30
!hi
<@zodbot:fedora.im>
18:01:31
Brad Smith: Brad Smith (buckaroogeek)
<@buckaroogeek:fedora.im>
18:01:52
Thanks for the review!
<@alexsaezm:fedora.im>
18:02:04
my pleasure 🙂
<@alexsaezm:fedora.im>
18:03:05
I needed to update/reinstall/migrate (long story) to a new Fedora installation and I have everything who knows where... hence the huge delay in the review.
<@buckaroogeek:fedora.im>
18:03:50
I usually reinstall Fedora from scratch every 3 or so versions
<@alexsaezm:fedora.im>
18:05:31
I don't have a consistent process (I usually stay in a version until it is more or less EOL and then jump). But in this case I needed to do some cleaning in the data and the tools I was using for reasons. A spring/summer cleaning is always nice.
<@alexsaezm:fedora.im>
18:06:58
5 minutes out. Right now we don't have anything tagged for the meeting. So we can move to the open floor.
<@alexsaezm:fedora.im>
18:07:05
!topic Open Floor
<@alexsaezm:fedora.im>
18:07:45
FYI: Rawhide has 1.27.0 right now (I still need to move that into f45)
<@alexsaezm:fedora.im>
18:07:50
and I will do a mass prebuild on COPR
<@buckaroogeek:fedora.im>
18:08:22
Ok. And retire go 1.25 in f43?
<@alexsaezm:fedora.im>
18:08:55
Yes, I need to open the ticket to move it to 1.26
<@alexsaezm:fedora.im>
18:09:00
let me write that down...
<@buckaroogeek:fedora.im>
18:09:43
That will be helpful. Kubernetes uses 1.26 for all supported releases
<@alexsaezm:fedora.im>
18:09:52
no more 1.25?
<@buckaroogeek:fedora.im>
18:10:41
No - the releases last week all moved to 1.26
<@alexsaezm:fedora.im>
18:11:18
I will open the ticket after this meeting then
<@alexsaezm:fedora.im>
18:12:31
Any other topics?
<@buckaroogeek:fedora.im>
18:14:08
Just a comment and question. The upstream cri-o project uses govulncheck output in openvex format. I have found that useful
<@buckaroogeek:fedora.im>
18:14:53
eg:
<@buckaroogeek:fedora.im>
18:14:53
```
<@buckaroogeek:fedora.im>
18:14:53
==> (lesspipe 2.27) append : to filename to view the original json file
<@buckaroogeek:fedora.im>
18:14:53
{
<@buckaroogeek:fedora.im>
18:14:53
"@context": "https://openvex.dev/ns/v0.2.0",
<@buckaroogeek:fedora.im>
18:14:53
"@id": "govulncheck/vex:c4453f6cf6f7c79cfaa3e35f9e2a5a40d5fed6430606c3975b1866206e7f8f53",
<@buckaroogeek:fedora.im>
18:14:53
"author": "Unknown Author",
<@buckaroogeek:fedora.im>
18:14:53
"timestamp": "2026-08-24T17:47:12.566052929Z",
<@buckaroogeek:fedora.im>
18:14:53
"version": 1,
<@buckaroogeek:fedora.im>
18:14:53
"tooling": "https://pkg.go.dev/golang.org/x/vuln/cmd/govulncheck",
<@buckaroogeek:fedora.im>
18:14:53
"statements": [
<@buckaroogeek:fedora.im>
18:14:53
{
<@buckaroogeek:fedora.im>
18:14:53
"vulnerability": {
<@buckaroogeek:fedora.im>
18:14:53
"@id": "https://pkg.go.dev/vuln/GO-2025-4096",
<@buckaroogeek:fedora.im>
18:14:53
"name": "GO-2025-4096",
<@buckaroogeek:fedora.im>
18:14:53
"description": "Container escape via \"masked path\" abuse due to mount race conditions in githu
<@buckaroogeek:fedora.im>
18:14:53
b.com/opencontainers/runc",
<@buckaroogeek:fedora.im>
18:14:53
"aliases": [
<@buckaroogeek:fedora.im>
18:14:53
"CVE-2025-31133",
<@buckaroogeek:fedora.im>
18:14:53
"GHSA-9493-h29p-rfm2"
<@buckaroogeek:fedora.im>
18:14:53
]
<@buckaroogeek:fedora.im>
18:14:53
},
<@buckaroogeek:fedora.im>
18:14:53
"products": [
<@buckaroogeek:fedora.im>
18:14:53
{
<@buckaroogeek:fedora.im>
18:14:53
"@id": "Unknown Product",
<@buckaroogeek:fedora.im>
18:14:53
"subcomponents": [
<@buckaroogeek:fedora.im>
18:14:53
{
<@buckaroogeek:fedora.im>
18:14:53
"@id": "pkg:golang/github.com%2Fopencontainers%2Frunc@v1.3.1"
<@buckaroogeek:fedora.im>
18:14:53
}
<@buckaroogeek:fedora.im>
18:14:53
]
<@buckaroogeek:fedora.im>
18:14:53
}
<@buckaroogeek:fedora.im>
18:14:53
],
<@buckaroogeek:fedora.im>
18:14:53
"status": "not_affected",
<@buckaroogeek:fedora.im>
18:14:53
"justification": "vulnerable_code_not_present",
<@buckaroogeek:fedora.im>
18:14:53
"impact_statement": "Govulncheck determined that the vulnerable code isn't called"
<@buckaroogeek:fedora.im>
18:14:53
},
<@buckaroogeek:fedora.im>
18:14:53
```
<@buckaroogeek:fedora.im>
18:16:11
So i modified the cri-o shell script to generate this output on a local source repository. Can share if any interest. Useful to me at least checking CVEs
<@buckaroogeek:fedora.im>
18:17:01
I will copy and paste the output into a cve BZ
<@alexsaezm:fedora.im>
18:17:49
I'm not familiar with this openvex format (if I was, I don't recall it)...
<@alexsaezm:fedora.im>
18:18:02
how are you using it?
<@buckaroogeek:fedora.im>
18:18:14
https://openssf.org/projects/openvex/
<@buckaroogeek:fedora.im>
18:19:13
Just to check BZ cves for a package. If the cve is not in the report I can close as not found. Otherwise if found I can annotate the BZ as confirmed
<@buckaroogeek:fedora.im>
18:20:11
The CRI-O team actually provides a copy of the vex report with each release documenting any known vulnerabilities
<@alexsaezm:fedora.im>
18:20:32
oh
<@alexsaezm:fedora.im>
18:20:34
I like this
<@alexsaezm:fedora.im>
18:21:03
I have a bunch of packages with a lot of old CVEs that I need to verify if they are still there. It's a slow manually process.
<@buckaroogeek:fedora.im>
18:22:04
Yes. the script i have generates 1 report which i can search with less or whatever. Quicker that running govulncheck on each cve
<@buckaroogeek:fedora.im>
18:23:02
if i was more talented i could write a script to go through each open BZ :)
<@buckaroogeek:fedora.im>
18:23:34
but maybe after BZ is retired and the new system put in place ...
<@buckaroogeek:fedora.im>
18:24:38
Just for background - here is the CRI-O write up: https://github.com/cri-o/cri-o?tab=security-ov-file#openvex
<@alexsaezm:fedora.im>
18:24:39
I'm not talented but I will waste hours in trying to not go over that list 😄 I like the idea a lot. Until now I was doing the checking manually (can explain why I have a lengthy list)
<@buckaroogeek:fedora.im>
18:26:13
I will share the script on Forgejo or somewhere like that. Unless you have another suggestion?
<@buckaroogeek:fedora.im>
18:26:26
Or github
<@alexsaezm:fedora.im>
18:27:13
no suggestions, thanks a lot!!
<@alexsaezm:fedora.im>
18:28:21
Anything else? we can call it if not 🙂
<@buckaroogeek:fedora.im>
18:28:32
Nothing else from me
<@alexsaezm:fedora.im>
18:28:39
in that case...
<@alexsaezm:fedora.im>
18:28:54
thanks a lot of the govulncheck idea! and see you around!
<@buckaroogeek:fedora.im>
18:29:03
¡Hasta luego!
<@alexsaezm:fedora.im>
18:29:04
!endmeeting