Merged
Conversation
Signed-off-by: douhunt <douhunt@protonmail.com>
Codecov Report
@@ Coverage Diff @@
## master #9561 +/- ##
==========================================
- Coverage 45.86% 45.79% -0.08%
==========================================
Files 221 222 +1
Lines 26309 26377 +68
==========================================
+ Hits 12067 12079 +12
- Misses 12586 12650 +64
+ Partials 1656 1648 -8
Continue to review full report at Codecov.
|
10 tasks
Member
|
@34fathombelow thanks for this! Just so we have a paper trail, did you use any particular source that we can cite as the reason for removing the no-longer-secure algorithms? |
crenshaw-dev
requested changes
Jun 2, 2022
Signed-off-by: Justin Marquis <34fathombelow@protonmail.com>
crenshaw-dev
approved these changes
Jun 3, 2022
Member
crenshaw-dev
left a comment
There was a problem hiding this comment.
LGTM! @jannfis can you take a look?
jannfis
approved these changes
Jun 5, 2022
Member
jannfis
left a comment
There was a problem hiding this comment.
LGTM, thanks @34fathombelow !
crenshaw-dev
pushed a commit
that referenced
this pull request
Jun 6, 2022
* chore: update Kex-Algorithms Signed-off-by: douhunt <douhunt@protonmail.com> * sorted kex-algorithms Signed-off-by: Justin Marquis <34fathombelow@protonmail.com> Co-authored-by: douhunt <douhunt@protonmail.com> Signed-off-by: Michael Crenshaw <michael@crenshaw.dev>
Member
|
Cherry-picked onto 2.4. |
88 tasks
crenshaw-dev
pushed a commit
to crenshaw-dev/argo-cd
that referenced
this pull request
Jul 26, 2022
Signed-off-by: douhunt <douhunt@protonmail.com> Co-authored-by: douhunt <douhunt@protonmail.com> Co-authored-by: Michael Crenshaw <michael@crenshaw.dev> Signed-off-by: Michael Crenshaw <michael@crenshaw.dev> chore: update Kex-Algorithms (argoproj#9561) * chore: update Kex-Algorithms Signed-off-by: douhunt <douhunt@protonmail.com> * sorted kex-algorithms Signed-off-by: 34FathomBelow <34fathombelow@protonmail.com> Co-authored-by: douhunt <douhunt@protonmail.com> Signed-off-by: Michael Crenshaw <michael@crenshaw.dev> chore upgrade base image for test containers Ubuntu:22.04 (argoproj#9563) Signed-off-by: 34FathomBelow <34fathombelow@protonmail.com>
crenshaw-dev
pushed a commit
to crenshaw-dev/argo-cd
that referenced
this pull request
Jul 26, 2022
Signed-off-by: douhunt <douhunt@protonmail.com> Co-authored-by: douhunt <douhunt@protonmail.com> Co-authored-by: Michael Crenshaw <michael@crenshaw.dev> Signed-off-by: Michael Crenshaw <michael@crenshaw.dev> chore: update Kex-Algorithms (argoproj#9561) * chore: update Kex-Algorithms Signed-off-by: douhunt <douhunt@protonmail.com> * sorted kex-algorithms Signed-off-by: 34FathomBelow <34fathombelow@protonmail.com> Co-authored-by: douhunt <douhunt@protonmail.com> Signed-off-by: Michael Crenshaw <michael@crenshaw.dev> chore upgrade base image for test containers Ubuntu:22.04 (argoproj#9563) Signed-off-by: 34FathomBelow <34fathombelow@protonmail.com>
crenshaw-dev
added a commit
that referenced
this pull request
Jul 26, 2022
Signed-off-by: douhunt <douhunt@protonmail.com> Co-authored-by: douhunt <douhunt@protonmail.com> Co-authored-by: Michael Crenshaw <michael@crenshaw.dev> Signed-off-by: Michael Crenshaw <michael@crenshaw.dev> chore: update Kex-Algorithms (#9561) * chore: update Kex-Algorithms Signed-off-by: douhunt <douhunt@protonmail.com> * sorted kex-algorithms Signed-off-by: 34FathomBelow <34fathombelow@protonmail.com> Co-authored-by: douhunt <douhunt@protonmail.com> Signed-off-by: Michael Crenshaw <michael@crenshaw.dev> chore upgrade base image for test containers Ubuntu:22.04 (#9563) Signed-off-by: 34FathomBelow <34fathombelow@protonmail.com> Co-authored-by: 34FathomBelow <34fathombelow@protonmail.com>
crenshaw-dev
added a commit
that referenced
this pull request
Jul 26, 2022
Signed-off-by: douhunt <douhunt@protonmail.com> Co-authored-by: douhunt <douhunt@protonmail.com> Co-authored-by: Michael Crenshaw <michael@crenshaw.dev> Signed-off-by: Michael Crenshaw <michael@crenshaw.dev> chore: update Kex-Algorithms (#9561) * chore: update Kex-Algorithms Signed-off-by: douhunt <douhunt@protonmail.com> * sorted kex-algorithms Signed-off-by: 34FathomBelow <34fathombelow@protonmail.com> Co-authored-by: douhunt <douhunt@protonmail.com> Signed-off-by: Michael Crenshaw <michael@crenshaw.dev> chore upgrade base image for test containers Ubuntu:22.04 (#9563) Signed-off-by: 34FathomBelow <34fathombelow@protonmail.com> Co-authored-by: 34FathomBelow <34fathombelow@protonmail.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Signed-off-by: douhunt douhunt@protonmail.com
Part 1 of 3 to upgrade base image to Ubuntu:22.04
This must be merged before #9551 and cherry-picked into 2.4
Upgraded golang.org/x/crypto libraries to support diffie-hellman-group14-sha256. I also removed two Kex-Algorithms which should no longer be used for security reasons. This may cause some breakage for a very very small group of users. I would also recommend removing diffie-hellman-group14-sha1 in the very near future (v2.5) and give users plenty of warning.
Note on DCO:
If the DCO action in the integration test fails, one or more of your commits are not signed off. Please click on the Details link next to the DCO action for instructions on how to resolve this.
Checklist: