-
Notifications
You must be signed in to change notification settings - Fork 18
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
deps: bump client-go from v0.24.2 to v0.25.0-alpha.2 #57
Conversation
@DmitriyLewen Does v0.24.3 happen to fix it? |
no, i checked it. |
@josedonizetti @chen-keinan Can you review it? I don't have permission in this repository. |
@DmitriyLewen I think we can use replace in for go.mod file instead if getting v0.25.0-alpha.2 , wdyt ? |
hmm... i don't know which is better. If you prefer to use replace - tell me, i will change PR. |
It is a direct dependency. We can update the version rather than the |
I'm ok also with both just prefer not to use |
Description
k8s.io/client-go
v0.24.x. containsgithub.com/emicklei/go-restful v2.9.5
with critical vulnerability CVE-2022-1996.Bumped
k8s.io/client-go
tov0.25.0-alpha.2
, until stable versionv0.25.0
is released.Related Issues: