-
Notifications
You must be signed in to change notification settings - Fork 2.4k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[v3.4 backport] Bump github.com/containers/psgo to v1.7.2 #13862
Conversation
Resolves: CVE-2022-1227 Upstream fix: containers/psgo#92 Signed-off-by: Lokesh Mandvekar <[email protected]>
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: lsm5 The full list of commands accepted by this bot can be found here.
Needs approval from an approver in each of these files:
Approvers can indicate their approval by writing |
This code requires golang 1.16. |
ugh .. i'll update it, thanks |
@vrothberg PTAL |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This bumps way to many dependencies for a backport, it should only include the fix.
Looking at psgo commit logs, there's only an extra Also, i guess backport is a misnomer here, since I didn't actually cherry-pick the commit from main, but manually ran |
No that would be fine for me, it is just that he current PR bumps minor and major versions such as c/storage which we should never do for patch releases unless absolutely necessary. Patch releases should only add bug/security fixes. |
All the BZs are assigned to me. I appreciate helping hands but note that it's already chaotic to handle. We need backports in psgo first. |
I started the backports. Need to go through |
Closing. I'll build podman for f35 only after we have v3.4 updated upstream. |
Resolves: CVE-2022-1227
Upstream fix: containers/psgo#92
Signed-off-by: Lokesh Mandvekar [email protected]
main branch is on v1.7.2 so that's what I bumped this branch to.
@mheon @rhatdan @vrothberg @TomSweeneyRedHat @Luap99 PTAL
/cc @containers/podman-maintainers