Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump prometheus/client_golang dependency to avoid CVE-2022-21698 #783

Merged
merged 4 commits into from
Mar 31, 2022
Merged

Bump prometheus/client_golang dependency to avoid CVE-2022-21698 #783

merged 4 commits into from
Mar 31, 2022

Conversation

agarcia-oss
Copy link
Member

Bump prometheus/client_golang dependency to avoid CVE-2022-21698

CVE-2022-21698 vulnerability affects the prometheus/client_golang dependency we declare in the go.mod manifest. Version 1.12.1 fixes the vulnerability.

Benefits

Improve the security posture of the project.

Possible drawbacks

If any, they should be detected by the integration tests

Additional information

Link to the CVE report: CVE-2022-21698

@agarcia-oss agarcia-oss changed the title Bump prometheus/client_golang dependency to avoid CVE-2022-21698 Draft: Bump prometheus/client_golang dependency to avoid CVE-2022-21698 Mar 25, 2022
@agarcia-oss agarcia-oss changed the title Draft: Bump prometheus/client_golang dependency to avoid CVE-2022-21698 Bump prometheus/client_golang dependency to avoid CVE-2022-21698 Mar 25, 2022
Copy link
Collaborator

@alvneiayu alvneiayu left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@agarcia-oss agarcia-oss self-assigned this Mar 28, 2022
@agarcia-oss agarcia-oss merged commit 2210fcf into bitnami-labs:main Mar 31, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants