Skip to content

[v12] - Backport Bump github.com/docker/distribution (#26107)#26854

Merged
reedloden merged 1 commit intobranch/v12from
jent/docker_distribution-v12
May 24, 2023
Merged

[v12] - Backport Bump github.com/docker/distribution (#26107)#26854
reedloden merged 1 commit intobranch/v12from
jent/docker_distribution-v12

Conversation

@jentfoo
Copy link
Copy Markdown
Contributor

@jentfoo jentfoo commented May 24, 2023

v12 backport of PR: #26107

This backport is necessary to address the following denial of service CVE: https://github.com/distribution/distribution/security/advisories//GHSA-hqxw-f8mx-cpmw

Bumps [github.com/docker/distribution](https://github.com/docker/distribution) from 2.8.1+incompatible to 2.8.2+incompatible.
- [Release notes](https://github.com/docker/distribution/releases)
- [Commits](distribution/distribution@v2.8.1...v2.8.2)

---
updated-dependencies:
- dependency-name: github.com/docker/distribution
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
@jentfoo jentfoo added security Security Issues dependencies Pull requests that update a dependency file sec-type-dos Security Vulnerability - Denial of Service labels May 24, 2023
@jentfoo jentfoo self-assigned this May 24, 2023
@reedloden reedloden added this pull request to the merge queue May 24, 2023
Merged via the queue into branch/v12 with commit 4d84803 May 24, 2023
@reedloden reedloden deleted the jent/docker_distribution-v12 branch May 24, 2023 19:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

backport dependencies Pull requests that update a dependency file sec-type-dos Security Vulnerability - Denial of Service security Security Issues size/sm

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants