-
Notifications
You must be signed in to change notification settings - Fork 15
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
fix vulnerability issues #149
Conversation
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
/lgtm
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: horis233, ZhuoxiLi The full list of commands accepted by this bot can be found here. The pull request process is described here
Needs approval from an approver in each of these files:
Approvers can indicate their approval by writing |
* bump operator version to 1.3.0 for release 3.9 (#110) * add deletecollection back (#111) * add skiprange for namespace-scope operator (#112) * bump version to 1.4.0 for release 3.10.0 (#115) * Bump golang from 1.15.7 to 1.16.6 (#114) Bumps golang from 1.15.7 to 1.16.6. --- updated-dependencies: - dependency-name: golang dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * trigger rebuild to fetch new base image (#116) * opt-in of ubi base image automated builds (#117) * opt-in of ubi base image automated builds * configure Docker Credential * Bump golang from 1.16.6 to 1.16.7 (#118) Bumps golang from 1.16.6 to 1.16.7. --- updated-dependencies: - dependency-name: golang dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * fix base image file name (#120) * add relatedImages to operator CSV (#119) * add relatedImages to operator CSV * follow CICD name convention * bump version to 1.5.0 (#122) * Bump golang from 1.16.7 to 1.17.0 (#121) Bumps golang from 1.16.7 to 1.17.0. --- updated-dependencies: - dependency-name: golang dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * update replace (#123) * Trigger build with new base image * Trigger build with new base image * bump version to 1.6.0 (#127) * Bump golang from 1.17.0 to 1.17.1 (#126) Bumps golang from 1.17.0 to 1.17.1. --- updated-dependencies: - dependency-name: golang dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * Trigger build with new base image * bump version to 1.7.0 and add bump csv script (#129) * Bump golang from 1.17.1 to 1.17.2 (#128) Bumps golang from 1.17.1 to 1.17.2. --- updated-dependencies: - dependency-name: golang dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * Trigger build with new base image * bump version to 1.8.0 (#134) * Bump golang from 1.17.2 to 1.17.3 (#133) Bumps golang from 1.17.2 to 1.17.3. --- updated-dependencies: - dependency-name: golang dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * fix minKubeVersion (#132) * Trigger build with new base image * go mod tidy for golang 1.17 (#135) * Trigger build with new base image * using specific verbs to replace wildcards (#137) * bump version to 1.9.0 (#139) * remove codcov (#141) * Bump golang from 1.17.3 to 1.17.6 (#143) Bumps golang from 1.17.3 to 1.17.6. --- updated-dependencies: - dependency-name: golang dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * Trigger build with new base image * Trigger build with new base image * Trigger build with new base image * update the copyrights for 2022 (#147) * fix vulnerability issues (#149) * bump version to 1.10.0 (#150) * Trigger build with new base image * Bump golang from 1.17.6 to 1.17.7 (#152) Bumps golang from 1.17.6 to 1.17.7. --- updated-dependencies: - dependency-name: golang dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * bump version to 1.11.0 (#155) * Trigger build with new base image * Bump golang from 1.17.7 to 1.18.0 (#157) Bumps golang from 1.17.7 to 1.18.0. --- updated-dependencies: - dependency-name: golang dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * summarize the runtime permission (#158) * summarize the runtime permission * summarize the runtime permission * format constant.go * fix lint err * list role within ns * format constant.go * Trigger build with new base image * remove label in nss-runtime-managed-role (#159) * bump nss version to 1.12.0 (#160) * Bump golang from 1.18.0 to 1.18.1 (#161) Bumps golang from 1.18.0 to 1.18.1. --- updated-dependencies: - dependency-name: golang dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * Trigger build with new base image * migrate to ICR (#162) * migrate to ICR * fix lint error * Trigger build with new base image * Trigger build with new base image * Add replaces back to CSV (#163) * bump version to 1.13.0 (#165) Co-authored-by: Yuchen Li <Yuchen.Li1@ibm.com> * Trigger build with new base image * remove horis233 from owner * bump version to 1.14.0 (#167) * bump version to 1.14.0 * remove ‘replace’ field for new release Co-authored-by: Yuchen-Li1 <Yuchen.Li1@ibm.com> * Trigger build with new base image * update tool dependency for code and manifest (#169) * set default value of csvinjector to true (#170) Co-authored-by: root <root@drowse1.fyre.ibm.com> * Trigger build with new base image * compatibility clause to NSS CRDs (#173) Signed-off-by: qpdpQ <liyuchen223@gmail.com> * Bump golang from 1.18.1 to 1.18.4 (#174) Bumps golang from 1.18.1 to 1.18.4. --- updated-dependencies: - dependency-name: golang dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * bump up version to 1.15.0 (#179) Signed-off-by: qpdpQ <liyuchen223@gmail.com> Signed-off-by: qpdpQ <liyuchen223@gmail.com> * Trigger build with new base image * Bump golang from 1.18.4 to 1.19.0 (#178) Bumps golang from 1.18.4 to 1.19.0. --- updated-dependencies: - dependency-name: golang dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * Trigger build with new base image * Bump golang from 1.19.0 to 1.19.1 (#182) Bumps golang from 1.19.0 to 1.19.1. --- updated-dependencies: - dependency-name: golang dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * update future version to 2.0.0 Signed-off-by: Daniel Fan <fanyuchensx@gmail.com> Signed-off-by: qpdpQ <liyuchen223@gmail.com> Signed-off-by: dependabot[bot] <support@github.com> Signed-off-by: Daniel Fan <fanyuchensx@gmail.com> Co-authored-by: Jiaming Hu <horis233@gmail.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Travis CI User <travis@example.org> Co-authored-by: Alice Li <zhuoxi.ibm@gmail.com> Co-authored-by: Yuchen Li <46284272+qpdpQ@users.noreply.github.com> Co-authored-by: Yuchen Li <Yuchen.Li1@ibm.com> Co-authored-by: YuChen Shen <59578388+YCShen1010@users.noreply.github.com> Co-authored-by: root <root@drowse1.fyre.ibm.com>
No description provided.