[Release/1.6] CVE-2022-1996 fix for go-restful#9385
[Release/1.6] CVE-2022-1996 fix for go-restful#9385estesp merged 1 commit intocontainerd:release/1.6from
Conversation
|
Hi @hightoxicity. Thanks for your PR. I'm waiting for a containerd member to verify that this patch is reasonable to test. If it is, they should reply with Once the patch is verified, the new status will be reflected by the I understand the commands that are listed here. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. |
1f1f19d to
97ac9bc
Compare
|
/test all |
|
@hightoxicity: Cannot trigger testing until a trusted user reviews the PR and leaves an DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. |
97ac9bc to
f18dede
Compare
|
Can you remove the accidental README change from the commit
|
f18dede to
515f1f7
Compare
| github.com/docker/go-events v0.0.0-20190806004212-e31b211e4f1c | ||
| github.com/docker/go-metrics v0.0.1 | ||
| github.com/docker/go-units v0.4.0 | ||
| github.com/docker/go-units v0.5.0 |
There was a problem hiding this comment.
Was this update related or a manual change? I notice that #9388 did not update this dependency
|
Hi @dmcgowan, sorry for the new line in the readme, I tried to force CI to rerun, I was thinking it was an unexpected failure. Thx |
….16.0 Signed-off-by: hightoxicity <[email protected]> Signed-off-by: Tony Fouchard <[email protected]>
515f1f7 to
62d4022
Compare
Kern--
left a comment
There was a problem hiding this comment.
This looks good to me, for what it's worth.
|
Thanks @thaJeztah, what is the process to get a 1.6.25 version tagged and available in nighly channels of the docker repositories (example: https://download.docker.com/linux/ubuntu/dists/jammy/pool/nightly/amd64/)? Maybe I can get some nightly binaries here https://github.com/containerd/containerd/actions/workflows/nightly.yml ? |
Remove CVE-2022-1996 from containerd binary upgrading go-restful to 2.16.0
GHSA-r48q-9g5r-8q2h