Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[bp/1.26] deps/CVE: Fix (nghttp2) CVE-2024-30255 #33338

Merged
merged 3 commits into from
Apr 4, 2024

Conversation

phlax
Copy link
Member

@phlax phlax commented Apr 4, 2024

Commit Message:
Additional Description:
Risk Level:
Testing:
Docs Changes:
Release Notes:
Platform Specific Features:
[Optional Runtime guard:]
[Optional Fixes #Issue]
[Optional Fixes commit #PR or SHA]
[Optional Deprecated:]
[Optional API Considerations:]

phlax and others added 2 commits April 4, 2024 12:08
Signed-off-by: Ryan Northey <ryan@synca.io>
Signed-off-by: Yan Avlasov <yavlasov@google.com>
Signed-off-by: Ryan Northey <ryan@synca.io>
@repokitteh-read-only repokitteh-read-only bot added the deps Approval required for changes to Envoy's external dependencies label Apr 4, 2024
Copy link

CC @envoyproxy/dependency-shepherds: Your approval is needed for changes made to (bazel/.*repos.*\.bzl)|(bazel/dependency_imports\.bzl)|(api/bazel/.*\.bzl)|(.*/requirements\.txt)|(.*\.patch).
envoyproxy/dependency-shepherds assignee is @htuch

🐱

Caused by: #33338 was opened by phlax.

see: more, trace.

GHSA-j654-3ccm-vfmm

Signed-off-by: Ryan Northey <ryan@synca.io>
@yanavlasov yanavlasov enabled auto-merge (squash) April 4, 2024 12:18
@phlax phlax disabled auto-merge April 4, 2024 12:27
@phlax phlax enabled auto-merge (rebase) April 4, 2024 12:27
@phlax phlax merged commit 3d2b7e2 into envoyproxy:release/v1.26 Apr 4, 2024
38 of 41 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
deps Approval required for changes to Envoy's external dependencies
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants