k3s/1.29.3-r1: cve remediation - #16429
Conversation
3878978 to
96be1ea
Compare
Signed-off-by: hectorj2f <hector@chainguard.dev>
96be1ea to
ed36eba
Compare
Package k3s: Click to expand/collapsePackage k3s: Package k3s-images: Click to expand/collapsePackage k3s-images: bincapz found differences: Click to expand/collapseChanged: k3s/bin/k3s
Changed: k3s/bin/_k3s-inner
|
Package k3s: Click to expand/collapsePackage k3s: Package k3s-images: Click to expand/collapsePackage k3s-images: bincapz found differences: Click to expand/collapseChanged: k3s/bin/k3s
Changed: k3s/bin/_k3s-inner
|
vaikas
left a comment
There was a problem hiding this comment.
Just curious if we need something else in our gobump so that we wouldn't need to do both bump, and patch the go files too. Having the patch file, I would assume will be harder to know when / how to remove old patches?
|
@vaikas The patch is used whenever we need to make some code changes. We could remove go.mod/sum files from the patch. However whenever there is an update, gobump unnecessary changes will be wiped out from the definition. Regarding the patch, I am sure our update bot does not check if it is needed anymore. |
|
Yeah, that makes sense about the code changes, and I was indeed only wondering about the go.sum/go.mod patches. |
Co-authored-by: staging-vpa-bot <staging-vpa-bot@chainguard.dev> Export: b8dab4b
k3s/1.29.3-r1: fix GHSA-c33x-xqrf-c478
Advisory data: https://github.com/wolfi-dev/advisories/blob/main/k3s.advisories.yaml