-
Notifications
You must be signed in to change notification settings - Fork 9.8k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Plan release v3.5.11 #16960
Comments
I've created slack thread https://kubernetes.slack.com/archives/C3HD8ARJ5/p1700180400783899 to invite contributors to form a small release team to help get This is a trial for creating more formal release teams for future etcd releases to help reduce workload of our current release managers for 3.5 and 3.4. |
Confirmed release team will be @serathius, @sharathsivakumar, @bsctl. @sharathsivakumar and @bsctl can you please reply to confirm your timezone so that @serathius can book the release publishing zoom/google meet call? Additionally - @sharathsivakumar and @bsctl it would be a huge help if you can begin listing what will be included in this release by reviewing changes to |
CET |
CEST |
Can we take this as a higher priority task? |
@ahrtr I am working on this along with @bsctl and @serathius . I am currently listing issues that need to be added for this release. I think I should be done by tomorrow. Then the next steps would be to look for backports and release it. |
We don't have to do it in 3.5.11. I am thinking it would be better to release 3.5.11 asap due to the two CVEs already resolved. |
@ahrtr Confirming here, the 2 CVE's fixed are: -GHSA-qppj-fm5r-hxr3 correct? |
Please see the current 3.5.11's changelog.
|
Here is the list of issues to be added for the release. Please review and let me know if changes are required. |
Looks good, @sharathsivakumar can you update the https://github.com/etcd-io/etcd/blob/main/CHANGELOG/CHANGELOG-3.5.md based on that? |
On it! |
@serathius we are ready to go proceed with the release. Details are here |
What would you like to be added?
We recently addressed CVE-2023-47108 and backported this to
release 3.5
in #16946.Given the CVSS score let's ship
3.5.11
quickly to enable downstream consumers to patch.We should also review recently merged changes to
main
andrelease-3.5
to confirm the list of any other included changes in the release.I propose for this release we also extend the release team beyond 3.5 release manager @serathius and ask for two community volunteers to shadow the process and assist getting the release shipped.
This will give our recently joined community members an opportunity to learn more about the current state of how etcd releases are shipped and contribute to getting release
3.5.11
out the door as quickly as we can.Why is this needed?
Ensure we patch vulnerabilities as soon as possible, grow our new contributors.
The text was updated successfully, but these errors were encountered: