Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

OCPBUGS-30696: Bump ocicrypt to v1.1.10 #8062

Merged
merged 1 commit into from
Apr 23, 2024

Conversation

kannon92
Copy link
Contributor

What type of PR is this?

/kind dependency-change

What this PR does / why we need it:

Update https://github.com/containers/ocicrypt/releases/tag/v1.1.10 to fix a potential DDOS with go-jose.

Which issue(s) this PR fixes:

Special notes for your reviewer:

This will probably need backports.

Does this PR introduce a user-facing change?

update ocicrypt to v1.1.10.

@kannon92 kannon92 requested a review from mrunalp as a code owner April 23, 2024 17:24
@openshift-ci openshift-ci bot added release-note Denotes a PR that will be considered when it comes time to generate release notes. dco-signoff: no Indicates the PR's author has not DCO signed all their commits. labels Apr 23, 2024
signed-off-by: Kevin Hannon <kehannon@redhat.com>
@openshift-ci openshift-ci bot added the kind/dependency-change Categorizes issue or PR as related to changing dependencies label Apr 23, 2024
@openshift-ci openshift-ci bot requested review from hasan4791 and klihub April 23, 2024 17:24
@openshift-ci openshift-ci bot added dco-signoff: yes Indicates the PR's author has DCO signed all their commits. and removed dco-signoff: no Indicates the PR's author has not DCO signed all their commits. labels Apr 23, 2024
@kannon92 kannon92 changed the title bump ocicrypt to v1.1.10 to fix CVE-2024-28180 for jose-go bump ocicrypt to v1.1.10 to fix potential ddos for jose-go Apr 23, 2024
@haircommander
Copy link
Member

/approve
/lgtm

@openshift-ci openshift-ci bot added the lgtm Indicates that a PR is ready to be merged. label Apr 23, 2024
Copy link
Contributor

openshift-ci bot commented Apr 23, 2024

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: haircommander, kannon92

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-ci openshift-ci bot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Apr 23, 2024
@kwilczynski kwilczynski changed the title bump ocicrypt to v1.1.10 to fix potential ddos for jose-go Bump ocicrypt to v1.1.10 Apr 23, 2024
@openshift-merge-bot openshift-merge-bot bot merged commit 944404a into cri-o:main Apr 23, 2024
68 of 69 checks passed
@kwilczynski
Copy link
Member

@kwilczynski kwilczynski changed the title Bump ocicrypt to v1.1.10 OCPBUGS-30696: Bump ocicrypt to v1.1.10 May 7, 2024
@openshift-ci-robot
Copy link

@kannon92: Jira Issue OCPBUGS-30696 is in an unrecognized state (Closed) and will not be moved to the MODIFIED state.

In response to this:

What type of PR is this?

/kind dependency-change

What this PR does / why we need it:

Update https://github.com/containers/ocicrypt/releases/tag/v1.1.10 to fix a potential DDOS with go-jose.

Which issue(s) this PR fixes:

Special notes for your reviewer:

This will probably need backports.

Does this PR introduce a user-facing change?

update ocicrypt to v1.1.10.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
approved Indicates a PR has been approved by an approver from all required OWNERS files. dco-signoff: yes Indicates the PR's author has DCO signed all their commits. kind/dependency-change Categorizes issue or PR as related to changing dependencies lgtm Indicates that a PR is ready to be merged. release-note Denotes a PR that will be considered when it comes time to generate release notes.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

4 participants