Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore: update git -> 2.43.4 and terraform -> 1.7.5 #13299

Merged
merged 1 commit into from
May 16, 2024

Conversation

coadler
Copy link
Member

@coadler coadler commented May 16, 2024

This fixes an RCE in git and gets us one minor version closer to fixing
a critical Terraform vulnerability. In the next release we'll bump to
1.8.x.

Fixes #13291

Copy link
Member Author

coadler commented May 16, 2024

This stack of pull requests is managed by Graphite. Learn more about stacking.

Join @coadler and the rest of your teammates on Graphite Graphite

@coadler coadler marked this pull request as ready for review May 16, 2024 16:54
@coadler coadler requested a review from kylecarbs May 16, 2024 16:55
@coadler coadler changed the title chore: update git -> 2.43.4 and terraform -> 1.7.3 chore: update git -> 2.43.4 and terraform -> 1.7.4 May 16, 2024
@matifali
Copy link
Collaborator

Why not jump to 1.7.5?

@coadler coadler changed the title chore: update git -> 2.43.4 and terraform -> 1.7.4 chore: update git -> 2.43.4 and terraform -> 1.7.5 May 16, 2024
install.sh Outdated Show resolved Hide resolved
@matifali
Copy link
Collaborator

A few more places:

  1. ARG TERRAFORM_VERSION=1.5.6
  2. RUN wget -O /tmp/terraform.zip "https://releases.hashicorp.com/terraform/1.6.6/terraform_1.6.6_linux_amd64.zip" && \

@coadler coadler force-pushed the colin/chore_update_git_-_2.43.4_and_terraform_-_1.7.3 branch from 4c5b659 to d2224e7 Compare May 16, 2024 18:49
This fixes an RCE in git and gets us one minor version closer to fixing
a critical Terraform vulnerability. In the next release we'll bump to
1.8.x.
@coadler coadler force-pushed the colin/chore_update_git_-_2.43.4_and_terraform_-_1.7.3 branch from d2224e7 to d3eba18 Compare May 16, 2024 18:49
@coadler coadler enabled auto-merge (squash) May 16, 2024 18:53
@coadler coadler merged commit 80538c0 into main May 16, 2024
30 of 33 checks passed
@coadler coadler deleted the colin/chore_update_git_-_2.43.4_and_terraform_-_1.7.3 branch May 16, 2024 19:07
@github-actions github-actions bot locked and limited conversation to collaborators May 16, 2024
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Critical CVE-2024-32002 and CVE-2024-3817 in Trivy Scan
3 participants