Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

Update various dependencies to mitigate CVE warnings #493

Merged
merged 4 commits into from
Nov 19, 2021
Merged

Conversation

hiddeco
Copy link
Member

@hiddeco hiddeco commented Nov 19, 2021

Because even if there is no impact whatsoever, we are nice people.

@hiddeco hiddeco added the area/ci CI related issues and pull requests label Nov 19, 2021
@hiddeco hiddeco changed the title Update containerd and image-spec dependencies Update various dependencies to mitigate CVE warnings Nov 19, 2021
To mitigate warnings for CVE-2021-41190 which effects both.

Signed-off-by: Hidde Beydals <hello@hidde.co>
This mitigates another warning for CVE-2017-11468, which is mostly
triggered because a part of Helm depends on it that our code paths
never reach.

Signed-off-by: Hidde Beydals <hello@hidde.co>
To mitigate warnings for CVE-2021-41092. Because even if there is no
impact whatsoever, we are nice people.

Signed-off-by: Hidde Beydals <hello@hidde.co>
Another patch for CVE-2021-41190.

Signed-off-by: Hidde Beydals <hello@hidde.co>
@hiddeco hiddeco merged commit cc2bc56 into main Nov 19, 2021
@hiddeco hiddeco deleted the update-deps branch November 19, 2021 13:31
# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
area/ci CI related issues and pull requests
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants