-
Notifications
You must be signed in to change notification settings - Fork 632
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
CVE found with v0.8.19 #926
Comments
Few more new CVE's
|
wondering someone would like to submit CL to update golang, go mod etc. to resolve those CVEs? |
This is covered by weekly deps update. It is usually auto generated on Fridays. |
@hakman does dep-bot update Go version as well? or just Go modules/pkgs? |
Looks like the dep-bot does not update golang version: #935 |
Can we please get an update on when to expect a new release with these CVEs fixed? |
Bump! It would be great to get a 0.8.20 release to address these CVEs in a tagged release |
Bump. Any update on when a new release might come out? |
Looks like golang version update in go.mod is not covered still. @jingxu97 are you able to take a look? |
We are still awaiting a 0.8.20 release for this. How do we go about expediting a new release? I see that the last 5 were within 3-4 months (i.e. less than 1 month per release), but it's now been over 4 months since 0.8.19, and we're getting flagged for CVEs until a new release is declared. |
We updated golang last week. @PelagicGames Can you help verify if all the CVEs are fixed at head commit? I can cut a new release this week after confirmation. |
Will try to do that today :) |
@wangzhen127 , I've just run a trivy scan and that's not showing any CVEs against head |
Thanks for the verification! We are investigating the presubmit issue #970. Will make a release after the fix. |
The issue is unblocked. Will make a new release later this week. |
v0.8.20 has been released. /close |
@wangzhen127: Closing this issue. In response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
Vulnerability scan shown a CVE for
NPD:v0.8.19
This issue is to log this and ask when this would be fixed
The text was updated successfully, but these errors were encountered: