Skip to content

[v12] Backport of Go Dependency Updates#33544

Merged
jentfoo merged 1 commit intobranch/v12from
jent/go_updates-v12
Oct 16, 2023
Merged

[v12] Backport of Go Dependency Updates#33544
jentfoo merged 1 commit intobranch/v12from
jent/go_updates-v12

Conversation

@jentfoo
Copy link
Copy Markdown
Contributor

@jentfoo jentfoo commented Oct 16, 2023

This change includes a variety of dependency updates, including the most recent HTTP/2 DoS CVE as well as some prior missed updates. Included CVEs:

OpenTelemetry update from this weekend is absent from this PR. I plan to follow up with another PR due to the interactions with grpc.

Comment thread assets/backport/go.mod Outdated
This change includes a variety of dependency updates, including the most recent HTTP/2 DoS CVE as well as some prior missed updates.  Included CVEs:
  * CVE-2023-28119 (was already updated in root go.mod)
  * CVE-2023-34231
  * CVE-2023-28840
  * CVE-2023-28841
  * CVE-2023-28842
@jentfoo jentfoo force-pushed the jent/go_updates-v12 branch from fa23ff2 to a75795f Compare October 16, 2023 20:16
@jentfoo jentfoo added this pull request to the merge queue Oct 16, 2023
@github-merge-queue github-merge-queue Bot removed this pull request from the merge queue due to failed status checks Oct 16, 2023
@jentfoo jentfoo added this pull request to the merge queue Oct 16, 2023
Merged via the queue into branch/v12 with commit 74063ca Oct 16, 2023
@jentfoo jentfoo deleted the jent/go_updates-v12 branch October 16, 2023 22:11
This was referenced Oct 18, 2023
@jentfoo jentfoo added the no-changelog Indicates that a PR does not require a changelog entry label Oct 20, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

backport no-changelog Indicates that a PR does not require a changelog entry size/sm

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants