Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

(deps): Update x/net library to v0.33.0 #2307

Merged
merged 1 commit into from
Dec 26, 2024
Merged

(deps): Update x/net library to v0.33.0 #2307

merged 1 commit into from
Dec 26, 2024

Conversation

jjbustamante
Copy link
Member

Summary

Fix critical vulnerability GHSA-w32m-9786-jp63

Output

Before

Version 0.36.0

Screenshot from 2024-12-26 07-49-53

After

Once the library is updated, we build the pack binaries and when running grype we get:

Screenshot from 2024-12-26 07-49-19

Documentation

  • Should this change be documented?
    • Yes, see #___
    • No

Related

Resolves #2304

Signed-off-by: Juan Bustamante <bustamantejj@gmail.com>
@github-actions github-actions bot added the type/chore Issue that requests non-user facing changes. label Dec 26, 2024
@github-actions github-actions bot added this to the 0.37.0 milestone Dec 26, 2024
@jjbustamante jjbustamante added dependencies Pull requests that update a dependency file cve and removed type/chore Issue that requests non-user facing changes. labels Dec 26, 2024
@jjbustamante jjbustamante modified the milestones: 0.37.0, 0.36.2 Dec 26, 2024
@jjbustamante jjbustamante marked this pull request as ready for review December 26, 2024 13:18
@jjbustamante jjbustamante requested review from a team as code owners December 26, 2024 13:18
@jjbustamante jjbustamante merged commit 78e6a7f into main Dec 26, 2024
16 checks passed
@jjbustamante jjbustamante deleted the deps/issue-2304 branch December 26, 2024 13:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
cve dependencies Pull requests that update a dependency file
Projects
None yet
Development

Successfully merging this pull request may close these issues.

CVE(s) found
1 participant