Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Release etcd 3.4.36 #19384

Closed
AwesomePatrol opened this issue Feb 11, 2025 · 4 comments
Closed

Release etcd 3.4.36 #19384

AwesomePatrol opened this issue Feb 11, 2025 · 4 comments

Comments

@ivanvc
Copy link
Member

ivanvc commented Feb 11, 2025

@ahrtr, do we want to release v3.4.36 now? Technically, the CVEs don't affect the project directly, i.e., see the result from govulncheck (but I guess some third party security/static checks may complain about etcd v3.4.35):

=== Module Results ===

Vulnerability #1: GO-2024-3333
    Non-linear parsing of case-insensitive content in golang.org/x/net/html
  More info: https://pkg.go.dev/vuln/GO-2024-3333
  Module: golang.org/x/net
    Found in: golang.org/x/[email protected]
    Fixed in: golang.org/x/[email protected]

Vulnerability #2: GO-2024-3321
    Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in
    golang.org/x/crypto
  More info: https://pkg.go.dev/vuln/GO-2024-3321
  Module: golang.org/x/crypto
    Found in: golang.org/x/[email protected]
    Fixed in: golang.org/x/[email protected]

Your code is affected by 0 vulnerabilities.
This scan also found 0 vulnerabilities in packages you import and 2
vulnerabilities in modules you require, but your code doesn't appear to call
these vulnerabilities.

@ahrtr
Copy link
Member

ahrtr commented Feb 11, 2025

@ahrtr, do we want to release v3.4.36 now?

3.4.35 was released 3 months ago. I think we should release new patch based on https://github.com/etcd-io/etcd/blob/main/Documentation/contributor-guide/release.md#patch-release-criteria

@ivanvc
Copy link
Member

ivanvc commented Feb 11, 2025

Sounds good. I'll replace this issue with a new one to control/edit its body.

Thanks, @AwesomePatrol, for bringing this up!

@ivanvc
Copy link
Member

ivanvc commented Feb 11, 2025

Superseded by #19393.

@ivanvc ivanvc closed this as completed Feb 11, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Development

No branches or pull requests

3 participants