Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

feat(build): add regex disable for packages in security update #5783

Merged
merged 1 commit into from
Jan 20, 2023

Conversation

slonka
Copy link
Contributor

@slonka slonka commented Jan 20, 2023

aws-sdk is released daily and this bug https://osv.dev/vulnerability/GO-2022-0646 has no fix since Feb 2022. This might be a bug in osv or an actuall bug on aws-sdk. Let's disable it for now and if dependabot detects a bug on master we will update manually release branches.

Signed-off-by: slonka [email protected]

Action output here: https://github.com/kumahq/kuma/actions/runs/3966613586. No PRs were created because there were no changes.

Checklist prior to review

  • Link to docs PR or issue --
  • Link to UI issue or PR --
  • Is the issue worked on linked? --
  • The PR does not hardcode values that might break projects that depend on kuma (e.g. "kumahq" as a image registry) --
  • The PR will work for both Linux and Windows, system specific functions like syscall.Mkfifo have equivalent implementation on the other OS --
  • Unit Tests --
  • E2E Tests --
  • Manual Universal Tests --
  • Manual Kubernetes Tests --
  • Do you need to update UPGRADE.md? --
  • Does it need to be backported according to the backporting policy? --
  • Do you need to explicitly set a > Changelog: entry here or add a ci/ label to run fewer/more tests?

Changelog: feat(security): add dependabot security updates to release branches

@slonka slonka added the ci/skip-test PR: Don't run unit and e2e tests (maybe this is just a doc change) label Jan 20, 2023
@slonka slonka requested review from a team, jakubdyszkiewicz and lukidzi and removed request for a team January 20, 2023 10:02
@slonka slonka changed the title feat(build): add regex disable feat(build): add regex disable for packages in security update Jan 20, 2023
@jakubdyszkiewicz
Copy link
Contributor

We are not affected by this CVE, right?

@slonka
Copy link
Contributor Author

slonka commented Jan 20, 2023

We are not affected by this CVE, right?

I don't think so, we don't use aws-sdk directly, I'll check what uses it. Also: even if we are, there is no fix for it :(

@slonka
Copy link
Contributor Author

slonka commented Jan 20, 2023

We are using golang-migrate which uses aws-sdk.

@jakubdyszkiewicz
Copy link
Contributor

yeah, but we only do migrations on postgres, so we don't use it

@slonka slonka merged commit feaf229 into master Jan 20, 2023
@slonka slonka deleted the feat-gh-action-security-update-add-ignore-list branch January 20, 2023 10:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
ci/skip-test PR: Don't run unit and e2e tests (maybe this is just a doc change)
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants