Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

build(dataflow): bump grpc-stub and grpc-protobuf to 1.57.2 #5110

Merged
merged 1 commit into from Aug 29, 2023

Conversation

adriangonz
Copy link
Contributor

What this PR does / why we need it:

Address CVE-2023-2976

Which issue(s) this PR fixes:

Fixes #

Special notes for your reviewer:

@adriangonz adriangonz requested a review from agrski August 29, 2023 10:24
@adriangonz adriangonz changed the title Bump grpc-stub and grpc-protobuf to 1.57.2 build(dataflow): bump grpc-stub and grpc-protobuf to 1.57.2 Aug 29, 2023
@adriangonz
Copy link
Contributor Author

On top of the CI tests, I've also done some manual integration tests with our sample notebooks and all seems good 👍

Copy link
Contributor

@agrski agrski left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

From my side, I've just checked the following:

make -C scheduler build-jvm
./gradlew build --refresh-dependencies
./gradlew test

and all these ran without issue. I'm not expecting any major issues from these dependencies being updated, so as long as the dataflow engine can connect to the scheduler, this all seems fine to me.

@adriangonz adriangonz merged commit 2b7d365 into SeldonIO:v2 Aug 29, 2023
4 of 6 checks passed
@adriangonz adriangonz deleted the dataflow-cves branch August 29, 2023 16:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants