-
Notifications
You must be signed in to change notification settings - Fork 187
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Update github.com/opencontainers/runc to v1.0.3 (fix CVE-2021-43784) #518
Conversation
Is there any specific format we can use to track the CVEs fixed so they can be made explicit in the "release changes"? |
Please undo these changes and bump the version in the replace section, add the CVE numbers there. |
fc9091d
to
25ae88b
Compare
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Please rebase with upstream main and force push.
25ae88b
to
914fc0d
Compare
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM
Thanks @pjbgf
PS. After we release source-controller with these changes, you can update IAC too.
@pjbgf I assumed you've run
|
Advisories fixed: github.com/opencontainers/runc: CVE-2021-43784 GO-2021-0085 GO-2021-0087 Signed-off-by: Paulo Gomes <paulo.gomes@weave.works>
914fc0d
to
058788b
Compare
The issue was with the containerd dependency, which I have now removed from the PR. Tested it locally and it is working fine now. 👍 |
Security Advisories fixed:
github.com/opencontainers/runc v1.0.3
IDs: CVE-2021-43784, GO-2021-0085, GO-2021-0087
Links:
GHSA-v95c-p5hm-xq8f