Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(deps): bump up opencontainers/runc to 1.1.12 #1043

Closed
wants to merge 1 commit into from

Conversation

thepetk
Copy link
Contributor

@thepetk thepetk commented Feb 14, 2024

Description

A bump up to the opencontainers/runc to its latest v1.1.12 version is needed, in order to patch the CVE-2024-21626.

Issue ticket number and link

This PR will allow the devfile registry to patch the CVE there too. Related devfile issue: devfile/api#1427

Type of change

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to not work as expected)
  • This change requires a documentation update

How Has This Been Tested?

Please describe the tests that you ran to verify your changes. Provide instructions so we can reproduce. Please also list any relevant details for your test configuration

Checklist:

  • I have performed a self-review of my code
  • I have commented my code, particularly in hard-to-understand areas
  • I have made corresponding changes to the documentation
  • I have added meaningful description with JIRA/GitHub issue key(if applicable), for example HASSuiteDescribe("STONE-123456789 devfile source")
  • I have updated labels (if needed)

@openshift-ci openshift-ci bot requested review from psturc and rhopp February 14, 2024 15:13
Copy link

openshift-ci bot commented Feb 14, 2024

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by:
Once this PR has been reviewed and has the lgtm label, please assign flacatus for approval. For more information see the Kubernetes Code Review Process.

The full list of commands accepted by this bot can be found here.

Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

Copy link

Quality Gate Passed Quality Gate passed

Issues
0 New issues

Measures
0 Security Hotspots
No data about Coverage
No data about Duplication

See analysis details on SonarCloud

@thepetk thepetk changed the title Bump up opencontainers/runc to 1.1.12 chore: bump up opencontainers/runc to 1.1.12 Feb 14, 2024
@thepetk thepetk changed the title chore: bump up opencontainers/runc to 1.1.12 chore(deps): bump up opencontainers/runc to 1.1.12 Feb 14, 2024
@thepetk
Copy link
Contributor Author

thepetk commented Feb 14, 2024

Closing for now as the devfile/registry#297 was opened

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant