Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Replace unmaintained UUID library #618

Merged
merged 4 commits into from
Mar 2, 2022
Merged

Conversation

srlobo
Copy link
Contributor

@srlobo srlobo commented Feb 28, 2022

Change github.com/satori/go.uuid to github.com/google/uuid. The former is not a
maintained library.

For reference: #617

@SuperQ
Copy link
Member

SuperQ commented Feb 28, 2022

This needs a DCO sign-off. You can use git commit -s --amend to add it.

Change github.com/satori/go.uuid to github.com/gofrs/uuid. The former is not a
maintained library, and since it has a critical vulnerability CVE-2021-3538
there's an ongoing discussion proposing to change it for the later.

Signed-off-by: Felix Ortega <[email protected]>
Signed-off-by: Felix Ortega <[email protected]>
@SuperQ
Copy link
Member

SuperQ commented Mar 1, 2022

The mixin failure is unrelated, will ignore it.

go.mod Outdated Show resolved Hide resolved
@SuperQ
Copy link
Member

SuperQ commented Mar 1, 2022

Just needs a go mod tidy.

Signed-off-by: Felix Ortega <[email protected]>
@SuperQ SuperQ changed the title Change uuid lib to fix vulnerability Replace unmaintained UUID library Mar 2, 2022
@SuperQ SuperQ merged commit 2d53711 into prometheus:main Mar 2, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants