Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

bump containernetworking/cni library to v0.8.1 - fix for CVE-2021-20206 #2974

Merged

Conversation

lsm5
Copy link
Member

@lsm5 lsm5 commented Feb 5, 2021

Signed-off-by: Lokesh Mandvekar [email protected]

What type of PR is this?

/kind other

What this PR does / why we need it:

Security fix for CVE-2021-20206 which affects containernetworking/cni library.

How to verify it

See: https://bugzilla.redhat.com/show_bug.cgi?id=1919391

Which issue(s) this PR fixes:

Fixes CVE-2021-20206

Special notes for your reviewer:

See: https://bugzilla.redhat.com/show_bug.cgi?id=1919391

Does this PR introduce a user-facing change?

None

@lsm5
Copy link
Member Author

lsm5 commented Feb 5, 2021

@TomSweeneyRedHat

@rhatdan
Copy link
Member

rhatdan commented Feb 5, 2021

/approve
/lgtm

@openshift-ci-robot
Copy link
Collaborator

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: lsm5, rhatdan

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-merge-robot openshift-merge-robot merged commit 17521db into containers:release-1.19 Feb 5, 2021
@lsm5
Copy link
Member Author

lsm5 commented Feb 5, 2021

@TomSweeneyRedHat @nalind @rhatdan can we cut a new release with this included please?

@TomSweeneyRedHat
Copy link
Member

@lsm5 yes, @rhatdan has a few PR's in flight too, once merged, he'll be cutting a new release. Most likely ready sometime Monday if not before.

@lsm5 lsm5 deleted the release-1.19-cni-bump branch February 5, 2021 21:17
@github-actions github-actions bot locked as resolved and limited conversation to collaborators Sep 24, 2023
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

5 participants