Skip to content

Update gogo/protobuf to v1.3.2#4974

Merged
estesp merged 1 commit intocontainerd:masterfrom
adisky:update-protobuf
Jan 28, 2021
Merged

Update gogo/protobuf to v1.3.2#4974
estesp merged 1 commit intocontainerd:masterfrom
adisky:update-protobuf

Conversation

@adisky
Copy link
Copy Markdown
Contributor

@adisky adisky commented Jan 27, 2021

bump version 1.3.2 for gogo/protobuf due to CVE-2021-3121 reported on gogo/protobuf version 1.3.1, CVE has been fixed for version 1.3.2

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3121

Signed-off-by: Aditi Sharma [email protected]

@k8s-ci-robot
Copy link
Copy Markdown

Hi @adisky. Thanks for your PR.

I'm waiting for a containerd member to verify that this patch is reasonable to test. If it is, they should reply with /ok-to-test on its own line. Until that is done, I will not automatically test new commits in this PR, but the usual testing commands by org members will still work. Regular contributors should join the org to skip this step.

Once the patch is verified, the new status will be reflected by the ok-to-test label.

I understand the commands that are listed here.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository.

@theopenlab-ci
Copy link
Copy Markdown

theopenlab-ci Bot commented Jan 27, 2021

Build succeeded.

@adisky adisky force-pushed the update-protobuf branch 2 times, most recently from 6999f80 to 5541d15 Compare January 28, 2021 05:48
@theopenlab-ci
Copy link
Copy Markdown

theopenlab-ci Bot commented Jan 28, 2021

Build succeeded.

@k8s-ci-robot
Copy link
Copy Markdown

@adisky: Cannot trigger testing until a trusted user reviews the PR and leaves an /ok-to-test message.

Details

In response to this:

/retest

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository.

@dims
Copy link
Copy Markdown
Member

dims commented Jan 28, 2021

/ok-to-test

@theopenlab-ci
Copy link
Copy Markdown

theopenlab-ci Bot commented Jan 28, 2021

Build succeeded.

bump version 1.3.2 for gogo/protobuf due to CVE-2021-3121 discovered
in gogo/protobuf version 1.3.1, CVE has been fixed in 1.3.2

Signed-off-by: Aditi Sharma <[email protected]>
@theopenlab-ci
Copy link
Copy Markdown

theopenlab-ci Bot commented Jan 28, 2021

Build succeeded.

@adisky adisky changed the title [WIP] Update gogo/protobuf to v1.3.2 Update gogo/protobuf to v1.3.2 Jan 28, 2021
@theopenlab-ci
Copy link
Copy Markdown

theopenlab-ci Bot commented Jan 28, 2021

Build succeeded.

@dims
Copy link
Copy Markdown
Member

dims commented Jan 28, 2021

LGTM

@dmcgowan @mikebrow can you please retrigger the flaky CI job?

thanks @adisky !

Copy link
Copy Markdown
Member

@estesp estesp left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

Copy link
Copy Markdown
Member

@mikebrow mikebrow left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@estesp
Copy link
Copy Markdown
Member

estesp commented Jan 28, 2021

This PR wins the prize for hitting both logged flaky test issues; we know neither is being impacted by this PR, and after 3 restarts we have run the full integration and test suites successfully across all the combinations. Going to merge.

@estesp estesp merged commit 19ee068 into containerd:master Jan 28, 2021
@dims
Copy link
Copy Markdown
Member

dims commented Jan 28, 2021

w00t thanks @estesp

Nice work @adisky

@thaJeztah
Copy link
Copy Markdown
Member

Cherry-picked in containerd/cri#1620 and #5018 (needs a vendor update of containerd/cri)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

cherry-picked/1.4.x PR commits are cherry picked into the release/1.4 branch ok-to-test

Projects

None yet

Development

Successfully merging this pull request may close these issues.

7 participants