Skip to content

[release/1.7] vendor: golang.org/x/[email protected]#10211

Merged
dmcgowan merged 6 commits intocontainerd:release/1.7from
austinvazquez:vendor-x-net-v0.23.0-to-release-1.7
May 13, 2024
Merged

[release/1.7] vendor: golang.org/x/[email protected]#10211
dmcgowan merged 6 commits intocontainerd:release/1.7from
austinvazquez:vendor-x-net-v0.23.0-to-release-1.7

Conversation

@austinvazquez
Copy link
Copy Markdown
Member

@austinvazquez austinvazquez commented May 10, 2024

Issue

Follow-up to #10204, release/1.7 is showing warnings from indirect dependency golang.org/x/net with recommendation to upgrade to golang.org/x/[email protected].

Description

This change vendors golang.org/x/[email protected] for the 1.7 release branch to resolve warnings for https://pkg.go.dev/vuln/GO-2024-2687.

Signed-off-by: Austin Vazquez [email protected]

@k8s-ci-robot
Copy link
Copy Markdown

Hi @austinvazquez. Thanks for your PR.

I'm waiting for a containerd member to verify that this patch is reasonable to test. If it is, they should reply with /ok-to-test on its own line. Until that is done, I will not automatically test new commits in this PR, but the usual testing commands by org members will still work. Regular contributors should join the org to skip this step.

Once the patch is verified, the new status will be reflected by the ok-to-test label.

I understand the commands that are listed here.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@austinvazquez austinvazquez force-pushed the vendor-x-net-v0.23.0-to-release-1.7 branch from 8d95a63 to f715516 Compare May 10, 2024 22:41
@austinvazquez austinvazquez marked this pull request as ready for review May 13, 2024 12:50
dependabot Bot and others added 5 commits May 13, 2024 13:29
Partial cherry-pick of 00d714e which
updates golang.org/x/sys from v0.16.0 to v0.18.0.

full diff: golang/sys@v0.16.0...v0.18.0

Signed-off-by: dependabot[bot] <[email protected]>
(cherry picked from commit 00d714e)
Signed-off-by: Austin Vazquez <[email protected]>
Partial cherry-pick of 228aa42 which
updates golang.org/x/term from v0.16.0 to v0.17.0.

full diff: golang/term@v0.16.0...v0.17.0

Signed-off-by: dependabot[bot] <[email protected]>
(cherry picked from commit 228aa42)
Signed-off-by: Austin Vazquez <[email protected]>
Partial cherry-pick of 7842161 which
updates golang.org/x/net from v0.17.0 to v0.19.0.

full diff: golang/net@v0.17.0...v0.19.0

Signed-off-by: Bryant Biggs <[email protected]>
(cherry picked from commit 7842161)
Signed-off-by: Austin Vazquez <[email protected]>
Partial cherry-pick of 5e3e12d which
updates golang.org/x/net from v0.19.0 to v0.20.0.

full diff: golang/net@v0.19.0...v0.20.0

Signed-off-by: dependabot[bot] <[email protected]>
(cherry picked from commit 5e3e12d)
Signed-off-by: Austin Vazquez <[email protected]>
Partial cherry-pick of 3a5b47d which
updates golang.org/x/net from v0.20.0 to v0.21.0 and golang/x/crypto
from v0.18.0 to v0.19.0

full diff:
- golang/net@v0.20.0...v0.21.0
- golang/crypto@v0.18.0...v0.19.0

Signed-off-by: dependabot[bot] <[email protected]>
(cherry picked from commit 3a5b47d)
Signed-off-by: Austin Vazquez <[email protected]>
@austinvazquez austinvazquez force-pushed the vendor-x-net-v0.23.0-to-release-1.7 branch from f715516 to 1eb0e37 Compare May 13, 2024 13:34
Partial cherry-pick of 1040c7b which
updates golang.org/x/net from v0.21.0 to v0.23.0, golang/x/crypto
from v0.19.0 to v0.21.0, and golang.org/x/term from v0.17.0 to v0.18.0.

full diff:
- golang/net@v0.21.0...v0.23.0
- golang/crypto@v0.19.0...v0.21.0
- golang/term@v0.17.0...v0.18.0

Signed-off-by: dependabot[bot] <[email protected]>
(cherry picked from commit 1040c7b)
Signed-off-by: Austin Vazquez <[email protected]>
@austinvazquez austinvazquez force-pushed the vendor-x-net-v0.23.0-to-release-1.7 branch from 1eb0e37 to f853bc1 Compare May 13, 2024 13:41
@dmcgowan dmcgowan merged commit 6f0f4df into containerd:release/1.7 May 13, 2024
@austinvazquez austinvazquez deleted the vendor-x-net-v0.23.0-to-release-1.7 branch May 13, 2024 15:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants