New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Automated cherry pick of #112693: Fixed (CVE-2022-27664) Bump golang.org/x/net to #113459
Automated cherry pick of #112693: Fixed (CVE-2022-27664) Bump golang.org/x/net to #113459
Conversation
Hi @aimuz. Thanks for your PR. I'm waiting for a kubernetes member to verify that this patch is reasonable to test. If it is, they should reply with Once the patch is verified, the new status will be reflected by the I understand the commands that are listed here. Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. |
/kind bug |
oh, that's irritating... the golang.org/x/sys update requires modifying go.mod to go1.18
that's why the analysis is failing... builds and unit tests also fail I guess I'll pick #109440 to release-1.24 separately, then this should work |
sorry for the conflicts, but if you replay the version bump on latest release-1.24, the verification errors should be resolved now |
Yes, he had to change to 1.18, can the 1.23 branch be changed? |
Not yet, 1.24 was already building with go1.18. Getting 1.23 onto go1.18 is more involved (see #113416) |
…07-c63010009c80 Fixed https://pkg.go.dev/vuln/GO-2022-0969 Signed-off-by: aimuz <mr.imuz@gmail.com>
62bc382
to
4e2d7a0
Compare
/retest |
@aimuz: The following test failed, say
Full PR test history. Your PR dashboard. Please help us cut down on flakes by linking to an open issue when you hit one in your PR. Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. I understand the commands that are listed here. |
|
that job's config was just modified in kubernetes/test-infra#27971 (comment), asked about it there |
/skip |
cc @kubernetes/release-managers |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
/lgtm
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: aimuz, cpanato, liggitt The full list of commands accepted by this bot can be found here. The pull request process is described here
Needs approval from an approver in each of these files:
Approvers can indicate their approval by writing |
Cherry pick of #112693 on release-1.24.
#112693: Fixed (CVE-2022-27664) Bump golang.org/x/net to
For details on the cherry pick process, see the cherry pick requests page.