Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[3.11.x] Update go-git dependency #1968

Merged
merged 1 commit into from
Jan 13, 2024
Merged

Conversation

hairyhenderson
Copy link
Owner

Back-porting #1962, to the 3.11.x branch, for GHSA-449p-3h89-pw88 (CVE-2023-49569). This is purely to quiet scanners, gomplate is not vulnerable since it only uses an in-memory filesystem when interacting with remote git servers.

Signed-off-by: Dave Henderson <[email protected]>
@hairyhenderson hairyhenderson enabled auto-merge (squash) January 13, 2024 20:04
@hairyhenderson hairyhenderson merged commit 6e709cf into 3.11.x Jan 13, 2024
11 of 15 checks passed
@hairyhenderson hairyhenderson deleted the go-git-update-3.11.x branch January 13, 2024 20:17
@seanorama
Copy link

seanorama commented Jan 20, 2024

@hairyhenderson Any chance of getting a release and image of this built?

While it may not be truly vulnerable, anyone using the latest release/image will report Critical CVEs.

In our case, we had to make our own build from the 3.11.x branch to remediate the CVE report.

@hairyhenderson
Copy link
Owner Author

@seanorama I'm working on releasing 3.11.7 now

ti-chi-bot bot referenced this pull request in PingCAP-QE/artifacts Jun 25, 2024
[![Mend
Renovate](https://app.renovatebot.com/images/banner.svg)](https://renovatebot.com)

This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
|
[hairyhenderson/gomplate](https://togithub.com/hairyhenderson/gomplate)
| final | patch | `v3.11.5` -> `v3.11.7` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

---

### Release Notes

<details>
<summary>hairyhenderson/gomplate (hairyhenderson/gomplate)</summary>

###
[`v3.11.7`](https://togithub.com/hairyhenderson/gomplate/releases/tag/v3.11.7)

[Compare
Source](https://togithub.com/hairyhenderson/gomplate/compare/v3.11.6...v3.11.7)

#### What's Changed

- \[3.11.x] Update go-git dependency by
[@&#8203;hairyhenderson](https://togithub.com/hairyhenderson) in
[https://github.com/hairyhenderson/gomplate/pull/1968](https://togithub.com/hairyhenderson/gomplate/pull/1968)

**Full Changelog**:
hairyhenderson/gomplate@v3.11.6...v3.11.7

###
[`v3.11.6`](https://togithub.com/hairyhenderson/gomplate/releases/tag/v3.11.6)

[Compare
Source](https://togithub.com/hairyhenderson/gomplate/compare/v3.11.5...v3.11.6)

#### What's Changed

- Backport Go 1.21 and security updates to 3.11.x by
[@&#8203;hairyhenderson](https://togithub.com/hairyhenderson) in
[https://github.com/hairyhenderson/gomplate/pull/1910](https://togithub.com/hairyhenderson/gomplate/pull/1910)
- backport: Add support for Linux s390x by
[@&#8203;hairyhenderson](https://togithub.com/hairyhenderson) in
[https://github.com/hairyhenderson/gomplate/pull/1909](https://togithub.com/hairyhenderson/gomplate/pull/1909)

**Full Changelog**:
hairyhenderson/gomplate@v3.11.5...v3.11.6

</details>

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Mend
Renovate](https://www.mend.io/free-developer-tools/renovate/). View
repository job log
[here](https://developer.mend.io/github/PingCAP-QE/artifacts).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzNy4yMDAuMCIsInVwZGF0ZWRJblZlciI6IjM3LjIwMC4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiJ9-->

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants