Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

backend: Update dependencies #1525

Merged
merged 2 commits into from
Nov 3, 2023
Merged

backend: Update dependencies #1525

merged 2 commits into from
Nov 3, 2023

Conversation

illume
Copy link
Collaborator

@illume illume commented Nov 3, 2023

This concentrates on updating dependencies with reported issues on artifact hub.

Mostly the issue is with helm and related things needing to be updated.

  ID SEVERITY PACKAGE VERSION FIXED IN
  CVE-2023-39325 HIGH golang.org/x/net v0.12.0 0.17.0
  GHSA-m425-mq94-257g HIGH google.golang.org/grpc v1.53.0 1.56.3, 1.57.1, 1.58.3
  GHSA-jq35-85cj-fj4p MEDIUM github.com/docker/docker v23.0.3+incompatible 24.0.7
  CVE-2023-3978 MEDIUM golang.org/x/net v0.12.0 0.13.0
  CVE-2023-44487 MEDIUM golang.org/x/net v0.12.0 0.17.0
  CVE-2023-44487 MEDIUM google.golang.org/grpc v1.53.0 1.58.3, 1.57.1, 1.56.3

Signed-off-by: René Dudfield <renedudfield@microsoft.com>
Signed-off-by: René Dudfield <renedudfield@microsoft.com>
@yolossn yolossn merged commit 618f562 into main Nov 3, 2023
7 checks passed
@joaquimrocha joaquimrocha deleted the dep-updates23113-backend branch November 3, 2023 13:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants