Skip to content

[BUG] Version of Go has security issues #508

@littlespice33

Description

@littlespice33

Describe the bug
The Doppler CLI is built with Go version 1.24.0 which contains multiple security vulnerabilities in its standard library. These vulnerabilities are flagged by third-party security scanners and can prevent organizations from passing security audits, including SOC2 certification.

To Reproduce
Install Doppler CLI into your deployed resources
Scan your resources with a 3rd party security system
See that it has concerns with the Go version, resulting in dozens of CVE security vulnerabilities, including CVE-2025-47907, CVE-2025-4674, and CVE-2025-58188. Almost all of these are because of vulnerabilities in stdlib

Expected behavior
Having no issues related to Go version on security audits

CLI Version:
Version 3.75.1

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions