Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Address CVE-2023-44487 / CVE-2023-39325 by upgrading Go & select deps #12661

Merged
merged 3 commits into from
Oct 23, 2023

Conversation

finnigja
Copy link
Contributor

Packer has no practical exposure to the HTTP/2 "rapid reset" denial of service (generic CVE-2023-44487 / Go-specific CVE-2023-39325), but we're bumping Go and affected dependencies to avoid scan noise.

@finnigja finnigja requested a review from a team as a code owner October 20, 2023 22:04
Copy link
Member

@nywilken nywilken left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good. Thanks for the bumping these.

@nywilken nywilken merged commit 9a1d4b5 into main Oct 23, 2023
11 checks passed
@nywilken nywilken deleted the bump_go_deps branch October 23, 2023 12:20
Copy link

I'm going to lock this pull request because it has been closed for 30 days ⏳. This helps our maintainers find and focus on the active issues.
If you have found a problem that seems related to this change, please open a new issue and complete the issue template so we can capture all the details necessary to investigate further.

@github-actions github-actions bot locked as resolved and limited conversation to collaborators Nov 23, 2023
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants