Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Enable auto-merge from branch-22.02 to branch-22.04 [skip ci] #4543

Merged
merged 1 commit into from
Jan 17, 2022

Conversation

pxLi
Copy link
Collaborator

@pxLi pxLi commented Jan 17, 2022

Signed-off-by: Peixin Li pxli@nyu.edu

Signed-off-by: Peixin Li <pxli@nyu.edu>
@pxLi pxLi added the build Related to CI / CD or cleanly building label Jan 17, 2022
@pxLi
Copy link
Collaborator Author

pxLi commented Jan 17, 2022

build

@NvTimLiu NvTimLiu self-requested a review January 17, 2022 06:01
@github-actions
Copy link

👎 Promotion blocked, new vulnerability found

Vulnerability report

Component Vulnerability Description Severity
Protocol Buffer Java API CVE-2021-22569 An issue in protobuf-java allowed the interleaving of com.google.protobuf.UnknownFieldSet fields in such a way that would be processed out of order. A small malicious payload can occupy the parser for several minutes by creating large numbers of short-lived objects that cause frequent, repeated pauses. We recommend upgrading libraries beyond the vulnerable versions. MEDIUM

@pxLi
Copy link
Collaborator Author

pxLi commented Jan 17, 2022

Going to force merge this one and draft another PR to fix the CVE-2021-22569

@pxLi pxLi merged commit 0dd67dd into NVIDIA:branch-22.02 Jan 17, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
build Related to CI / CD or cleanly building
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants