Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Backport of security: bump envoy version and k8s.io/apimachinery into release/1.18.x #21034

Merged

Conversation

dduzgun-security
Copy link
Contributor

Description

Upgrade to support Envoy 1.27.5, and 1.28.3.
This resolves CVE-2024-32475 (auto_sni).

Upgrade to support k8s.io/apimachinery to to v0.18.7 or higher.
This resolves CVE-2020-8559.

PR Checklist

  • updated test coverage
  • external facing docs updated
  • appropriate backport labels added
  • not a security concern

@github-actions github-actions bot added type/ci Relating to continuous integration (CI) tooling for testing or releases pr/dependencies PR specifically updates dependencies of project theme/contributing Additions and enhancements to community contributing materials labels May 2, 2024
@zalimeni zalimeni enabled auto-merge (squash) May 2, 2024 21:53
@zalimeni zalimeni merged commit 8da1b65 into release/1.18.x May 2, 2024
83 checks passed
@zalimeni zalimeni deleted the backport/security/net-7785/envoy-apimachinery/1.18.x branch May 2, 2024 22:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
pr/dependencies PR specifically updates dependencies of project pr/no-backport theme/contributing Additions and enhancements to community contributing materials type/ci Relating to continuous integration (CI) tooling for testing or releases
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants