Skip to content

dependencies: update cve_scan.py for some libcurl 7.74.0 false positives#14572

Merged
mattklein123 merged 1 commit intoenvoyproxy:masterfrom
htuch:curl-7.74-false-positives
Jan 6, 2021
Merged

dependencies: update cve_scan.py for some libcurl 7.74.0 false positives#14572
mattklein123 merged 1 commit intoenvoyproxy:masterfrom
htuch:curl-7.74-false-positives

Conversation

@htuch
Copy link
Member

@htuch htuch commented Jan 6, 2021

Needed since the CVE scan heuristics use relative release data /
CVE publish dates, and these CVEs were published after the 7.74.0
release.

Signed-off-by: Harvey Tuch htuch@google.com

…ves.

Needed since the CVE scan heuristics use relative release data /
CVE publish dates, and these CVEs were published after the 7.74.0
release.

Signed-off-by: Harvey Tuch <htuch@google.com>
@mattklein123 mattklein123 merged commit d0d926f into envoyproxy:master Jan 6, 2021
mpuncel added a commit to mpuncel/envoy that referenced this pull request Jan 8, 2021
* master: (48 commits)
  Resolve 14506, avoid libidn2 for our curl dependency (envoyproxy#14601)
  fix new/free mismatch in Mainthread utility (envoyproxy#14596)
  opencensus: deprecate Zipkin configuration. (envoyproxy#14576)
  upstream: clean up code location (envoyproxy#14580)
  configuration impl: add cast for ios compilation (envoyproxy#14590)
  buffer impl: add cast for android compilation (envoyproxy#14589)
  ratelimit: add dynamic metadata to ratelimit response (envoyproxy#14508)
  tcp_proxy: wait for CONNECT response before start streaming data (envoyproxy#14317)
  stream info: cleanup address handling (envoyproxy#14432)
  [deps] update upb to latest commit (envoyproxy#14582)
  Add utility to check whether the execution is in main thread. (envoyproxy#14457)
  listener: undeprecate bind_to_port (envoyproxy#14480)
  Fix data race in overload integration test (envoyproxy#14586)
  deps: update PGV (envoyproxy#14571)
  dependencies: update cve_scan.py for some libcurl 7.74.0 false positives. (envoyproxy#14572)
  Network::Connection: Add L4 crash dumping support (envoyproxy#14509)
  ssl: remember stat names for configured ciphers. (envoyproxy#14534)
  formatter: add custom date formatting to downstream cert start and end dates (envoyproxy#14502)
  feat(lua): allow setting response body when the upstream response body is empty (envoyproxy#14486)
  Generalize the gRPC access logger base classes (envoyproxy#14469)
  ...

Signed-off-by: Michael Puncel <mpuncel@squareup.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants