Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

dependency: Bumps golang.org/x/image from 0.11.0 to 0.18.0 #18366

Merged
merged 1 commit into from
Jul 26, 2024

Conversation

ivanvc
Copy link
Member

@ivanvc ivanvc commented Jul 25, 2024

Although our code is not vulnerable to GO-2024-2937/CVE-2024-24792, it is reported in the OpenSSF Scorecard.

Our CI didn't catch it because govulncheck exits with zero, as it doesn't detect that the code is vulnerable: https://prow.k8s.io/view/gs/kubernetes-jenkins/pr-logs/pull/etcd-io_etcd/18365/pull-etcd-govulncheck/1816510574830292992#.

Initially opened by dependabot (#18237). But I don't have permission to re-open the pull request.

Part of #18362.

Please read https://github.com/etcd-io/etcd/blob/main/CONTRIBUTING.md#contribution-flow.

@ahrtr
Copy link
Member

ahrtr commented Jul 26, 2024

/test pull-etcd-integration-1-cpu-amd64

@ahrtr
Copy link
Member

ahrtr commented Jul 26, 2024

gonum.org/v1/plot already resolved GO-2024-2937 / CVE-2024-24792 by bumping the golang.org/x/image to v0.18.0.
gonum/plot@69eb92b

GHSA-9phm-fm57-rhg8

@k8s-ci-robot
Copy link

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: ahrtr, ivanvc

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@ahrtr ahrtr merged commit 94d4744 into etcd-io:main Jul 26, 2024
46 checks passed
@ivanvc ivanvc deleted the update-golang.org-x-image-to-0.18.0 branch July 26, 2024 14:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Development

Successfully merging this pull request may close these issues.

3 participants