Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[3.4] Security: address HIGH Vulnerabilities #15019

Merged
merged 5 commits into from
Dec 19, 2022

Commits on Dec 19, 2022

  1. deps: bump github.com/gogo/protobuf to 1.3.2 to address CVE CVE-2021-…

    …3121
    
    Signed-off-by: Benjamin Wang <wachao@vmware.com>
    ahrtr committed Dec 19, 2022
    Configuration menu
    Copy the full SHA
    fcb048d View commit details
    Browse the repository at this point in the history
  2. deps: bump github.com/prometheus/client_golang to 1.11.1 to address CVE

    CVE-2022-21698
    
    Signed-off-by: Benjamin Wang <wachao@vmware.com>
    ahrtr committed Dec 19, 2022
    Configuration menu
    Copy the full SHA
    40566d9 View commit details
    Browse the repository at this point in the history
  3. deps: bump golang.org/x/net to 0.0.0-20220906165146-f3363e06e74c to a…

    …ddress CVE CVE-2021-44716 and CVE-2022-27664
    
    Signed-off-by: Benjamin Wang <wachao@vmware.com>
    ahrtr committed Dec 19, 2022
    Configuration menu
    Copy the full SHA
    68a5543 View commit details
    Browse the repository at this point in the history
  4. deps: bump golang.org/x/net to v0.4.0

    Signed-off-by: Benjamin Wang <wachao@vmware.com>
    ahrtr committed Dec 19, 2022
    Configuration menu
    Copy the full SHA
    86479c5 View commit details
    Browse the repository at this point in the history
  5. bump go version to 1.17.3

    Signed-off-by: Benjamin Wang <wachao@vmware.com>
    ahrtr committed Dec 19, 2022
    Configuration menu
    Copy the full SHA
    5413ce4 View commit details
    Browse the repository at this point in the history