Skip to content

chore: upgrade openresty version to 1.25.3.2#11419

Merged
shreemaan-abhishek merged 4 commits into
apache:masterfrom
shreemaan-abhishek:upgrade-openresty-version
Jul 30, 2024
Merged

chore: upgrade openresty version to 1.25.3.2#11419
shreemaan-abhishek merged 4 commits into
apache:masterfrom
shreemaan-abhishek:upgrade-openresty-version

Conversation

@shreemaan-abhishek

@shreemaan-abhishek shreemaan-abhishek commented Jul 22, 2024

Copy link
Copy Markdown
Contributor

Description

Version 1.25.3.1 contains a CVE. https://openresty.org/en/ann-1025003002.html

The openresty version upgrade is done by upgrading APISIX runtime to 1.2.1, the new APISIX runtime version uses openresty v1.25.3.2.

Proof that the version upgrade works:

Checklist

  • I have explained the need for this PR and the problem it solves
  • I have explained the changes or the new features added to this PR
  • I have added tests corresponding to this change
  • I have updated the documentation to reflect this change
  • I have verified that this change is backward compatible (If not, please discuss on the APISIX mailing list first)

@membphis membphis left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

one PR for one thing

I think you'd better split this PR to two separate PRs.

the 1: upgrade openresty version
the 2: remove grpc related code

@shreemaan-abhishek
shreemaan-abhishek marked this pull request as ready for review July 24, 2024 02:17
@Revolyssup
Revolyssup self-requested a review July 30, 2024 04:39

@membphis membphis left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants