-
Notifications
You must be signed in to change notification settings - Fork 2.1k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Cut patch release 0.34.1 #7131
Cut patch release 0.34.1 #7131
Conversation
158da38
to
bc112fb
Compare
1、In the replace of go.mod, due to weaveworks/common#239, The grpc version is 1.45.0, but there are vulnerabilities in this version. In order to fix CVE-2023-44478, the grpc version needs to be upgraded to 1.57.2 2、In order to upgrade GRPC, the version of weaveworks/common also needs to be upgraded, otherwise the build will fail Signed-off-by: hanyuting8 <[email protected]> Signed-off-by: Michael Hoffmann <[email protected]>
Signed-off-by: Michael Hoffmann <[email protected]>
bc112fb
to
4a4b669
Compare
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM!
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
f28680c you can also cherry pick this to fix the docs check
The link has moved to another since Cisco bought Banzai Cloud. Signed-off-by: Giedrius Statkevičius <[email protected]> Signed-off-by: Michael Hoffmann <[email protected]>
cherry picked the commit too |
Should we get https://github.com/thanos-io/thanos/pull/7134in? |
lets defer for 0.34.2 and/or 0.35 soon |
Changes
Cherry-picked 058f920 to address this CVE on 0.34 and f28680c to fix the documentation CI check.
Verification