Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgraded all modules to the latest version #2663

Merged
merged 2 commits into from
Jun 10, 2024

Conversation

pierluigilenoci
Copy link
Contributor

Description

A clumsy attempt to update all software CVEs.

Fix #2660, #2661 and #2662

Motivation and Context

To have the software free of any CVEs

How Has This Been Tested?

Using pipeline tests, no local test.

Checklist:

  • My change requires a change to the documentation or CHANGELOG.
  • I have updated the documentation/CHANGELOG accordingly.
  • I have created a feature (non-master) branch for my PR.
  • I have written tests for my code changes.

@pierluigilenoci pierluigilenoci requested a review from a team as a code owner June 10, 2024 09:31
@github-actions github-actions bot added the dependencies Pull requests that update a dependency file label Jun 10, 2024
@kvanzuijlen
Copy link
Member

Please run make verify-generate locally

@github-actions github-actions bot added the docs label Jun 10, 2024
@kvanzuijlen kvanzuijlen added the LGTM PR is ready to merge label Jun 10, 2024
Copy link
Member

@kvanzuijlen kvanzuijlen left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@pierluigilenoci
Copy link
Contributor Author

@kvanzuijlen, thank you. But someone had to approve it.

@pierluigilenoci
Copy link
Contributor Author

@JoelSpeed or @tuunit, could you please take a look?

Copy link
Member

@JoelSpeed JoelSpeed left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for syncing this up

@JoelSpeed JoelSpeed merged commit 5c315cd into oauth2-proxy:master Jun 10, 2024
9 checks passed
@pierluigilenoci pierluigilenoci deleted the CVE_fix branch June 10, 2024 10:00
@karatkep
Copy link

Hello @pierluigilenoci , @JoelSpeed,
Could you please share when this change will be released?

@pierluigilenoci
Copy link
Contributor Author

@karatkep I'm sorry, but I am not part of the maintainer of this repo; I don't have this information.
I was waiting for the release, too.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file docs LGTM PR is ready to merge
Projects
None yet
Development

Successfully merging this pull request may close these issues.

[Bug]: CVE-2024-24786 google.golang.org/protobuf
4 participants