[release/1.6] upgrade OpenTelemetry to v1.21.0 / v0.46.0 (CVE-2023-47108) etc.#9707
Conversation
|
Hi @aepifanov. Thanks for your PR. I'm waiting for a containerd member to verify that this patch is reasonable to test. If it is, they should reply with Once the patch is verified, the new status will be reflected by the I understand the commands that are listed here. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. |
e8ef5c8 to
d777aad
Compare
Signed-off-by: Andrey Epifanov <[email protected]>
full diff: golang/sys@v0.13.0...v0.16.0 Signed-off-by: Andrey Epifanov <[email protected]>
full diff: golang/term@v0.13.0...v0.16.0 Signed-off-by: Andrey Epifanov <[email protected]>
full diff: golang/crypto@v0.14.0...v0.18.0 Signed-off-by: Andrey Epifanov <[email protected]>
This is a false alarm. containerd does not use x/crypto for SSH. |
|
/ok-to-test |
|
Is there an equivalent PR for the 1.7 release branch? (looks like that one is on an older version) |
Fixing the following CVEs:
v0.46.0 /usr/bin/containerd