Skip to content

go.mod: golang.org/x/* latest#5855

Merged
AkihiroSuda merged 1 commit intomoby:masterfrom
AkihiroSuda:deps
Apr 9, 2025
Merged

go.mod: golang.org/x/* latest#5855
AkihiroSuda merged 1 commit intomoby:masterfrom
AkihiroSuda:deps

Conversation

@AkihiroSuda
Copy link
Copy Markdown
Member

For https://pkg.go.dev/vuln/GO-2025-3487 (x/crypto, unlikely affect BuildKit?)

@github-actions github-actions Bot added the area/dependencies Pull requests that update a dependency file label Mar 19, 2025
@tonistiigi tonistiigi requested a review from thaJeztah March 19, 2025 17:30
@AkihiroSuda
Copy link
Copy Markdown
Member Author

removed the needs-cherry-pick/v0.20 label

This seems still worth cherrypicking to silence vulnerability scanners

@tonistiigi
Copy link
Copy Markdown
Member

This seems still worth cherrypicking to silence vulnerability scanners

If the CVEs do not apply, then I think it is not worth the risk of breaking users in a patch release just to silence some wrong report from a scanner.

cc @thaJeztah if this can be merged into master.

Signed-off-by: Akihiro Suda <akihiro.suda.cz@hco.ntt.co.jp>
@AkihiroSuda
Copy link
Copy Markdown
Member Author

Rebased

Copy link
Copy Markdown
Member

@thaJeztah thaJeztah left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

had a look at the diffs, and didn't see anything immediately concerning; also opened moby/moby#49777 on the moby side

@AkihiroSuda AkihiroSuda merged commit 40a5c2d into moby:master Apr 9, 2025
112 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants