Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2023-44487: trigger new release builds #14506

Closed
30 tasks done
ReToCode opened this issue Oct 11, 2023 · 7 comments
Closed
30 tasks done

CVE-2023-44487: trigger new release builds #14506

ReToCode opened this issue Oct 11, 2023 · 7 comments

Comments

@ReToCode
Copy link
Member

ReToCode commented Oct 11, 2023

CVE-2023-44487 requires us to rebuild our currently supported releases:

knative/serving

knative/networking

knative-sandbox/net-istio

knative-sandbox/net-contour

knative-sandbox/net-gateway-api

knative-sandbox/net-kourier

knative-sandbox/net-certmanager

knative-sandbox/net-http01

/cc @skonto @nak3 @KauzClay @dprotaso @davidhadas

@ReToCode ReToCode added kind/question Further information is requested and removed kind/question Further information is requested labels Oct 11, 2023
@dprotaso dprotaso modified the milestone: v1.12.0 Oct 11, 2023
@dprotaso
Copy link
Member

cherry picking is broken - seems like we need to update prow

https://cloud-native.slack.com/archives/C04LY4M2G49/p1696866925712799

@dprotaso
Copy link
Member

ok - prow updated cherry picking is working again

@dprotaso
Copy link
Member

Ok branches are all up to date - will leave this issue open until the point releases are out

@dprotaso
Copy link
Member

looks like we also need to bump x/net to v0.17.0

see: https://groups.google.com/g/golang-announce/c/iNNxDTCjZvo

golang.org/x/net/http2 v0.17.0,

@ReToCode
Copy link
Member Author

@dprotaso I think we have it all now?

@nak3 thanks for your help!

@ReToCode
Copy link
Member Author

PR for depending image: brancz/kube-rbac-proxy#261

@skonto
Copy link
Contributor

skonto commented Nov 8, 2023

@ReToCode should we close this one?

@ReToCode ReToCode closed this as completed Nov 8, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants