[release/1.7] deps: update golang.org/x/#11178
[release/1.7] deps: update golang.org/x/#11178mxpv merged 1 commit intocontainerd:release/1.7from ErikJiang:update_crypto
Conversation
|
Hi @ErikJiang. Thanks for your PR. I'm waiting for a containerd member to verify that this patch is reasonable to test. If it is, they should reply with Once the patch is verified, the new status will be reflected by the I understand the commands that are listed here. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
|
@ErikJiang, to be clear neither of the CVEs listed affect containerd as it does not use either |
Signed-off-by: bo.jiang <[email protected]>
backport: #11145
during a vulnerability scan of containerd version 1.7.24,
we found that the
golang.org/x/cryptopackage has vulnerabilitiesCVE-2022-30636andCVE-2024-45337.to eliminate these false positives, we need updating the relevant dependency versions.
full diff: