Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix(deps): update kubernetes-client to fix CVE-2024-21534 #2459

Merged

Conversation

kim-tsao
Copy link
Member

@kim-tsao kim-tsao commented Oct 30, 2024

Manual cherry pick of #2356

Fixes:
https://issues.redhat.com/browse/RHIDP-4440

This upgrades the following packages

  • ocm-backend
  • shared-react
  • kubernetes-action
  • topology
  • tekton

Note: 1.3.x fix for Argocd will be contributed from backstage/community-plugin.

Fix CVE

CVE-2024-21534

@kim-tsao kim-tsao requested review from a team, debsmita1 and divyanshiGupta as code owners October 30, 2024 01:31
Copy link

changeset-bot bot commented Oct 30, 2024

🦋 Changeset detected

Latest commit: d49c76f

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 12 packages
Name Type
@janus-idp/backstage-scaffolder-backend-module-kubernetes Patch
@janus-idp/shared-react Patch
@janus-idp/backstage-plugin-ocm-backend Patch
@janus-idp/backstage-plugin-topology Patch
@janus-idp/backstage-plugin-tekton Patch
@janus-idp/backstage-plugin-acr Patch
@janus-idp/backstage-plugin-bulk-import Patch
@janus-idp/backstage-plugin-jfrog-artifactory Patch
@janus-idp/backstage-plugin-nexus-repository-manager Patch
@janus-idp/backstage-plugin-openshift-image-registry Patch
@janus-idp/backstage-plugin-quay Patch
@janus-idp/backstage-plugin-rbac Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

Copy link

sonarcloud bot commented Oct 30, 2024

Copy link
Member

@Fortune-Ndlovu Fortune-Ndlovu left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@openshift-ci openshift-ci bot added the lgtm label Oct 30, 2024
@openshift-merge-bot openshift-merge-bot bot merged commit 4aebf4e into janus-idp:release-1.3 Oct 30, 2024
11 checks passed
@kim-tsao kim-tsao deleted the release-1.3_CVE-2024-21534 branch November 20, 2024 20:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants