Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update dependencies to fix security vulnerability CVE-2023-32731 #1180

Closed
4 tasks
michael-valdron opened this issue Jul 6, 2023 · 8 comments
Closed
4 tasks
Assignees
Labels
area/library Common devfile library for interacting with devfiles area/registry Devfile registry for stacks and infrastructure status/wontfix This will not be worked on

Comments

@michael-valdron
Copy link
Member

michael-valdron commented Jul 6, 2023

Which area/kind this issue is related to?

/area library
/area registry

Issue Description

There is a recent reported high level security vulnerability CVE-2023-32731 which effects gRPC.

The following modules should have the dependency google.golang.org/grpc updated:

Target Date: TBA

@michael-valdron
Copy link
Member Author

All PRs for this issue are created with the vulnerability patch and are ready for review.

@michael-valdron michael-valdron moved this from In Progress 🚧 to In Review 👀 in Devfile Project Jul 19, 2023
@michael-valdron
Copy link
Member Author

Blocked due to the direct dependency not patching this yet: devfile/registry-operator#44 (comment)

@michael-valdron
Copy link
Member Author

michael-valdron commented Jul 19, 2023

This commit which is currently under kubernetes staging should provide a patch for this: kubernetes/kubernetes@a045fed

@michael-valdron
Copy link
Member Author

Direct dependencies now have patches so will unblock this issue.

@michael-valdron michael-valdron moved this from In Review 👀 to In Progress 🚧 in Devfile Project Jul 25, 2023
@michael-valdron
Copy link
Member Author

Revising PRs for review next sprint.

@michael-valdron
Copy link
Member Author

No updates as of late due to focus on other tasks.

@michael-valdron michael-valdron moved this from In Progress 🚧 to To Do 📝 in Devfile Project Aug 1, 2023
@michael-valdron
Copy link
Member Author

Continuing in Sprint 245 due to vacation leave.

@michael-valdron
Copy link
Member Author

After consideration on this issue, I have decided to defer this to be part of #1237 and will close this item.

@michael-valdron michael-valdron moved this from To Do 📝 to Done ✅ in Devfile Project Aug 31, 2023
@michael-valdron michael-valdron added the status/wontfix This will not be worked on label Sep 14, 2023
@michael-valdron michael-valdron closed this as not planned Won't fix, can't repro, duplicate, stale Sep 15, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
area/library Common devfile library for interacting with devfiles area/registry Devfile registry for stacks and infrastructure status/wontfix This will not be worked on
Projects
Status: Done ✅
Development

No branches or pull requests

1 participant