Skip to content

THREESCALE-10280 Bump dependencies to address otelhttp CVE#956

Merged
carlkyrillos merged 1 commit into3scale:masterfrom
carlkyrillos:THREESCALE-10280
Mar 29, 2024
Merged

THREESCALE-10280 Bump dependencies to address otelhttp CVE#956
carlkyrillos merged 1 commit into3scale:masterfrom
carlkyrillos:THREESCALE-10280

Conversation

@carlkyrillos
Copy link
Copy Markdown
Contributor

Issue Link

JIRA: THREESCALE-10280

What

This PR bumps k8s.io/* to v0.29.0, controller-runtime to v0.17.2, and github.com/RHsyseng/operator-utils to v1.4.13 to in order to bring the opentelemetry-go subdepdency to v0.44.0 which addresses CVE-2023-45142.

Verification Steps

Passing prow checks and eye review

@carlkyrillos carlkyrillos requested a review from a team as a code owner March 25, 2024 19:53
@carlkyrillos
Copy link
Copy Markdown
Contributor Author

Putting on a hold on this PR until #948 is merged

/hold

@carlkyrillos carlkyrillos force-pushed the THREESCALE-10280 branch 2 times, most recently from 2bc276a to db82ed8 Compare March 28, 2024 15:06
@carlkyrillos
Copy link
Copy Markdown
Contributor Author

Removing the hold since #948 was merged
/unhold

@carlkyrillos
Copy link
Copy Markdown
Contributor Author

/test test-e2e

@MStokluska
Copy link
Copy Markdown
Contributor

/lgtm

@carlkyrillos carlkyrillos merged commit fb8af7c into 3scale:master Mar 29, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants