Skip to content

[v13] - Backport Bump github.com/docker/distribution (#26107)#26855

Merged
reedloden merged 1 commit intobranch/v13from
jent/docker_distribution-v13
May 24, 2023
Merged

[v13] - Backport Bump github.com/docker/distribution (#26107)#26855
reedloden merged 1 commit intobranch/v13from
jent/docker_distribution-v13

Conversation

@jentfoo
Copy link
Copy Markdown
Contributor

@jentfoo jentfoo commented May 24, 2023

v13 backport of PR: #26107

This backport is necessary to address the following denial of service CVE: https://github.com/distribution/distribution/security/advisories//GHSA-hqxw-f8mx-cpmw

Bumps [github.com/docker/distribution](https://github.com/docker/distribution) from 2.8.1+incompatible to 2.8.2+incompatible.
- [Release notes](https://github.com/docker/distribution/releases)
- [Commits](distribution/distribution@v2.8.1...v2.8.2)

---
updated-dependencies:
- dependency-name: github.com/docker/distribution
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
@jentfoo jentfoo added security Security Issues dependencies Pull requests that update a dependency file sec-type-dos Security Vulnerability - Denial of Service labels May 24, 2023
@jentfoo jentfoo self-assigned this May 24, 2023
@codingllama
Copy link
Copy Markdown
Contributor

Thanks, Mike!

@reedloden reedloden added this pull request to the merge queue May 24, 2023
Merged via the queue into branch/v13 with commit d0b60b4 May 24, 2023
@reedloden reedloden deleted the jent/docker_distribution-v13 branch May 24, 2023 19:51
@r0mant r0mant mentioned this pull request Jul 14, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

backport dependencies Pull requests that update a dependency file sec-type-dos Security Vulnerability - Denial of Service security Security Issues size/sm

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants