Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update golang.org/x/crypto to latest #13996

Merged
merged 1 commit into from
May 5, 2022

Conversation

cmurphy
Copy link
Contributor

@cmurphy cmurphy commented Apr 28, 2022

Update crypto to address CVE-2022-27191.

The CVE fix is added in 0.0.0-20220315160706-3147a52a75dd but this
change updates to latest.

Backport of #13969

Update crypto to address CVE-2022-27191.

The CVE fix is added in 0.0.0-20220315160706-3147a52a75dd but this
change updates to latest.
@cmurphy
Copy link
Contributor Author

cmurphy commented Apr 28, 2022

Not sure if this 3.5 backport will be accepted due to this comment #13969 (review)

Usually bumping to the newest version (released on Apr 11, 2022) is not a good practice

so I'm open to changing this or closing it.

@ptabor
Copy link
Contributor

ptabor commented Apr 29, 2022

Not sure if this 3.5 backport will be accepted due to this comment #13969 (review)

Usually bumping to the newest version (released on Apr 11, 2022) is not a good practice

I don't think we have a policy on this, especially if we talk about official golang libraries that has high adoption and high bar on backward compatibility.

@ptabor ptabor merged commit 8453b10 into etcd-io:release-3.5 May 5, 2022
lavacat pushed a commit to lavacat/etcd that referenced this pull request Jun 29, 2022
Update crypto to address CVE-2022-27191.

The CVE fix is added in 0.0.0-20220315160706-3147a52a75dd but this
change updates to latest.

Backport of etcd-io#13996
lavacat pushed a commit to lavacat/etcd that referenced this pull request Jun 29, 2022
Update crypto to address CVE-2022-27191.

The CVE fix is added in 0.0.0-20220315160706-3147a52a75dd but this
change updates to latest.

Backport of etcd-io#13996

Signed-off-by: Bogdan Kanivets <bkanivets@apple.com>
lavacat pushed a commit to lavacat/etcd that referenced this pull request Jul 1, 2022
Update crypto to address CVE-2022-27191.

The CVE fix is added in 0.0.0-20220315160706-3147a52a75dd but this
change updates to latest.

Backport of etcd-io#13996

Signed-off-by: Bogdan Kanivets <bkanivets@apple.com>
tjungblu pushed a commit to tjungblu/etcd that referenced this pull request Sep 8, 2022
Update crypto to address CVE-2022-27191.

The CVE fix is added in 0.0.0-20220315160706-3147a52a75dd but this
change updates to latest.

Backport of etcd-io#13996

Signed-off-by: Bogdan Kanivets <bkanivets@apple.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Development

Successfully merging this pull request may close these issues.

None yet

3 participants