Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump prometheus/client_golang and crypto dependencies #831

Merged
merged 1 commit into from
Apr 28, 2022

Conversation

agarcia-oss
Copy link
Member

Description of the change

Bump prometheus/client_golang dependency to avoid CVE-2022-21698 and crypto dependency to avoid CVE-2022-27191

Benefits

Avoid security scanning issues and keeping up to date some dependencies
Possible drawbacks

None

Copy link
Collaborator

@alvneiayu alvneiayu left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@agarcia-oss agarcia-oss merged commit 6494002 into bitnami-labs:main Apr 28, 2022
@agarcia-oss agarcia-oss deleted the fix/cryptovulnb branch April 28, 2022 08:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Address vulnerability CVE-2022-27191 in the latest image of the Controller
2 participants