Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

THREESCALE-10280 Bump dependencies to address otelhttp CVE #212

Merged
merged 1 commit into from
Mar 25, 2024

Conversation

carlkyrillos
Copy link
Contributor

@carlkyrillos carlkyrillos commented Mar 22, 2024

Issue Link

JIRA: THREESCALE-10280

What

This PR bumps k8s.io/* to v0.29.0, controller-runtime to v0.17.2, and github.com/RHsyseng/operator-utils to v1.4.13 to in order to bring the opentelemetry-go subdepdency to v0.44.0 which addresses CVE-2023-45142.

Verification Steps

Passing prow checks and eye review

@carlkyrillos carlkyrillos requested a review from a team as a code owner March 22, 2024 18:06
@carlkyrillos carlkyrillos changed the title [WIP] THREESCALE-10280 Bump dependencies to address otelhttp CVE THREESCALE-10280 Bump dependencies to address otelhttp CVE Mar 22, 2024
@carlkyrillos carlkyrillos merged commit b419bd7 into 3scale:master Mar 25, 2024
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants