Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We鈥檒l occasionally send you account related emails.

Already on GitHub? Sign in to your account

馃悰 [fix]: Bump patch version of k8s deps to address CVE-2023-44487 #3665

Merged

Commits on Oct 20, 2023

  1. [fix]: Bump patch version of k8s deps to address CVE-2023-44487

    This PR bumps the dependencies that address the CVE-2023-44487.
    For more details on the htt2 rapid reset CVE refer:
    https://nvd.nist.gov/vuln/detail/CVE-2023-44487
    
    For more details on what these bumps contain, refer:
    1. Controller-runtime 0.16.3: https://github.com/kubernetes-sigs/controller-runtime/releases/tag/v0.16.3
    2. Kubernetes 1.28.3: kubernetes/apimachinery@be91880
    3. Kube-rbac-proxy 0.15.0: https://github.com/brancz/kube-rbac-proxy/releases/tag/v0.15.0
    
    Signed-off-by: Varsha Prasad Narsing <varshaprasad96@gmail.com>
    varshaprasad96 committed Oct 20, 2023
    Configuration menu
    Copy the full SHA
    e349099 View commit details
    Browse the repository at this point in the history