Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update deps #631

Merged
merged 4 commits into from
Nov 11, 2024
Merged

Update deps #631

merged 4 commits into from
Nov 11, 2024

Conversation

mostafa
Copy link
Member

@mostafa mostafa commented Nov 11, 2024

Ticket(s)

N/A

Description

This PR updates OpenSSL to 3.3.2-r1 in an attempt to fix CVE-2024-9143⁠. It also updates the softprops/action-gh-release action to v2. This also fixes issues reported by the linters.

Related PRs

N/A

Development Checklist

  • I have added a descriptive title to this PR.
  • I have squashed related commits together.
  • I have rebased my branch on top of the latest main branch.
  • I have performed a self-review of my own code.
  • I have commented on my code, particularly in hard-to-understand areas.
  • I have added docstring(s) to my code.
  • I have made corresponding changes to the documentation (docs).
  • I have updated docs using make gen-docs command.
  • I have added tests for my changes.
  • I have signed all the commits.

Legal Checklist

Copy link

github-actions bot commented Nov 11, 2024

Overview

Image reference ghcr.io/gatewayd-io/gatewayd:59b4b48 gatewaydio/gatewayd:latest
- digest c886b3d6f68f 80f3e87db481
- tag 59b4b48 latest
- provenance 7f47dca
- vulnerabilities critical: 0 high: 0 medium: 1 low: 0 critical: 0 high: 0 medium: 1 low: 0
- platform linux/amd64 linux/amd64
- size 20 MB 17 MB (-2.2 MB)
- packages 135 131 (-4)
Base Image alpine:3
also known as:
3.20
3.20.3
latest
alpine:3.20
also known as:
3
3.20.3
latest
- vulnerabilities critical: 0 high: 0 medium: 1 low: 0 critical: 0 high: 0 medium: 1 low: 0
Packages and Vulnerabilities (5 package changes and 0 vulnerability changes)
  • ➖ 3 packages removed
  • ♾️ 2 packages changed
  • 126 packages unchanged
Changes for packages of type apk (3 changes)
Package Version
ghcr.io/gatewayd-io/gatewayd:59b4b48
Version
gatewaydio/gatewayd:latest
ca-certificates 20240705-r0
openssl 3.3.2-r0
pax-utils 1.3.7-r2
Changes for packages of type golang (2 changes)
Package Version
ghcr.io/gatewayd-io/gatewayd:59b4b48
Version
gatewaydio/gatewayd:latest
♾️ github.com/gatewayd-io/gatewayd (devel) 0.0.0-20241109120212-7f47dca74c26
♾️ stdlib go1.23.3 1.23.3

@mostafa mostafa merged commit 6184a83 into main Nov 11, 2024
5 checks passed
@mostafa mostafa deleted the update-deps branch November 11, 2024 11:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant