Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bumping k8s apiserver to v0.25.5 #1148

Open
wants to merge 1 commit into
base: v0.44.x
Choose a base branch
from
Open

Conversation

sethiyash
Copy link
Contributor

What this PR does / why we need it:

Which issue(s) this PR fixes:

Fixes #

Does this PR introduce a user-facing change?


Additional Notes for your reviewer:

Review Checklist:
  • Follows the developer guidelines
  • Relevant tests are added or updated
  • Relevant docs in this repo added or updated
  • Relevant carvel.dev docs added or updated in a separate PR and there's
    a link to that PR
  • Code is at least as readable and maintainable as it was before this
    change

Additional documentation e.g., Proposal, usage docs, etc.:


Signed-off-by: sethiyash <yashsethiya97@gmail.com>
@neil-hickey neil-hickey reopened this Aug 15, 2023
@@ -16,7 +16,7 @@ require (
gopkg.in/yaml.v3 v3.0.1 // indirect
k8s.io/api v0.25.5
k8s.io/apimachinery v0.25.5
k8s.io/apiserver v0.25.0
k8s.io/apiserver v0.25.5

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Curious on why specifically 0.25.5? Wondering if these k8s deps could be bumped to the latest patch version for 1.25 release instead (0.25.15) which also contains partial fixes for the http2 rapid-reset CVE-2023-44487 (kubernetes/kubernetes#121201)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
Status: In Progress
Development

Successfully merging this pull request may close these issues.

None yet

3 participants