Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump golang.org/x/net to address CVE-2023-44487 #261

Merged
merged 2 commits into from
Oct 16, 2023

Conversation

ReToCode
Copy link
Contributor

@ReToCode ReToCode commented Oct 12, 2023

Changes

@joelanford
Copy link

Also bump

go-version: '1.21.1'
to 1.21.3?

Copy link
Collaborator

@s-urbaniak s-urbaniak left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm from my side 👍

@s-urbaniak
Copy link
Collaborator

@ibihim not sure if we have other golang references as well

@ibihim
Copy link
Collaborator

ibihim commented Oct 16, 2023

The one in go.mod, but this is a minimal go version flag.

@ibihim ibihim merged commit 188f80a into brancz:master Oct 16, 2023
7 checks passed
@varshaprasad96
Copy link

Could we also have release with this fix in?

varshaprasad96 added a commit to varshaprasad96/kubebuilder that referenced this pull request Oct 16, 2023
The 0.14.4 version of kube-rbac-proxy contains the fix for
CVE-2023-44487 by bumping golang.org/x/net.

For more details visit: brancz/kube-rbac-proxy#261

Signed-off-by: Varsha Prasad Narsing <varshaprasad96@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

5 participants