Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix: Resolve CVE-2022-32149 #406

Merged
merged 1 commit into from
Dec 6, 2022
Merged

fix: Resolve CVE-2022-32149 #406

merged 1 commit into from
Dec 6, 2022

Conversation

denis-tingaikin
Copy link
Member

Signed-off-by: denis-tingaikin denis.tingajkin@xored.com

Motivation

Some of NSM apps based on sdk-k8s have indirect dep for golang.org/x/text v0.3.7 ( that has CVE issue). It makes CVE checkers mad (the dep is not used by binary).

For example:

https://github.com/networkservicemesh/cmd-exclude-prefixes-k8s/blob/main/go.mod#L58
https://github.com/networkservicemesh/cmd-registry-k8s/blob/main/go.mod#L67

This PR should resolve the problem

Signed-off-by: denis-tingaikin <denis.tingajkin@xored.com>
@edwarnicke edwarnicke merged commit 0bd1359 into main Dec 6, 2022
nsmbot pushed a commit to networkservicemesh/cmd-admission-webhook-k8s that referenced this pull request Dec 6, 2022
…k-k8s@main

PR link: networkservicemesh/sdk-k8s#406

Commit: 0bd1359
Author: Ed Warnicke
Date: 2022-12-06 17:32:29 -0600
Message:
  - Merge pull request #406 from networkservicemesh/fix-cve-2022-32149
Signed-off-by: NSMBot <nsmbot@networkservicmesh.io>
nsmbot pushed a commit to networkservicemesh/cmd-registry-k8s that referenced this pull request Dec 6, 2022
…k-k8s@main

PR link: networkservicemesh/sdk-k8s#406

Commit: 0bd1359
Author: Ed Warnicke
Date: 2022-12-06 17:32:29 -0600
Message:
  - Merge pull request #406 from networkservicemesh/fix-cve-2022-32149
Signed-off-by: NSMBot <nsmbot@networkservicmesh.io>
nsmbot pushed a commit to networkservicemesh/cmd-forwarder-sriov that referenced this pull request Dec 6, 2022
…k-k8s@main

PR link: networkservicemesh/sdk-k8s#406

Commit: 0bd1359
Author: Ed Warnicke
Date: 2022-12-06 17:32:29 -0600
Message:
  - Merge pull request #406 from networkservicemesh/fix-cve-2022-32149
Signed-off-by: NSMBot <nsmbot@networkservicmesh.io>
nsmbot pushed a commit to networkservicemesh/cmd-exclude-prefixes-k8s that referenced this pull request Dec 6, 2022
…k-k8s@main

PR link: networkservicemesh/sdk-k8s#406

Commit: 0bd1359
Author: Ed Warnicke
Date: 2022-12-06 17:32:29 -0600
Message:
  - Merge pull request #406 from networkservicemesh/fix-cve-2022-32149
Signed-off-by: NSMBot <nsmbot@networkservicmesh.io>
nsmbot pushed a commit to networkservicemesh/cmd-forwarder-ovs that referenced this pull request Dec 6, 2022
…k-k8s@main

PR link: networkservicemesh/sdk-k8s#406

Commit: 0bd1359
Author: Ed Warnicke
Date: 2022-12-06 17:32:29 -0600
Message:
  - Merge pull request #406 from networkservicemesh/fix-cve-2022-32149
Signed-off-by: NSMBot <nsmbot@networkservicmesh.io>
nsmbot pushed a commit to networkservicemesh/cmd-forwarder-vpp that referenced this pull request Dec 6, 2022
…k-k8s@main

PR link: networkservicemesh/sdk-k8s#406

Commit: 0bd1359
Author: Ed Warnicke
Date: 2022-12-06 17:32:29 -0600
Message:
  - Merge pull request #406 from networkservicemesh/fix-cve-2022-32149
Signed-off-by: NSMBot <nsmbot@networkservicmesh.io>
nsmbot pushed a commit to networkservicemesh/cmd-nse-supplier-k8s that referenced this pull request Dec 6, 2022
…k-k8s@main

PR link: networkservicemesh/sdk-k8s#406

Commit: 0bd1359
Author: Ed Warnicke
Date: 2022-12-06 17:32:29 -0600
Message:
  - Merge pull request #406 from networkservicemesh/fix-cve-2022-32149
Signed-off-by: NSMBot <nsmbot@networkservicmesh.io>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants