Skip to content

Cut a new release with quic-go 0.48.2 #744

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed
jimmykarily opened this issue Dec 6, 2024 · 3 comments
Closed

Cut a new release with quic-go 0.48.2 #744

jimmykarily opened this issue Dec 6, 2024 · 3 comments
Labels
need/triage Needs initial labeling and prioritization

Comments

@jimmykarily
Copy link

Security scanners have started complaining about quic-go (https://osv.dev/vulnerability/GO-2024-3302) and it needs to be bumped to v0.48.2. This is already bumped in this repository but there is no tag/release for this yet.

I want to open PRs on dependant projects to fix this but it's better if there is a release to bump to (bumping to arbitrary commits from master might not get those PRs accepted)

e.g. this project needs the bump

Background: our Kairos pipelines are failing security scans: https://github.com/kairos-io/kairos/actions/runs/12194383948/job/34018136463?pr=3055

@jimmykarily jimmykarily added the need/triage Needs initial labeling and prioritization label Dec 6, 2024
Copy link

welcome bot commented Dec 6, 2024

Thank you for submitting your first issue to this repository! A maintainer will be here shortly to triage and review.
In the meantime, please double-check that you have provided all the necessary information to make this process easy! Any information that can help save additional round trips is useful! We currently aim to give initial feedback within two business days. If this does not happen, feel free to leave a comment.
Please keep an eye on how this issue will be labeled, as labels give an overview of priorities, assignments and additional actions requested by the maintainers:

  • "Priority" labels will show how urgent this is for the team.
  • "Status" labels will show if this is ready to be worked on, blocked, or in progress.
  • "Need" labels will indicate if additional input or analysis is required.

Finally, remember to use https://discuss.ipfs.io if you just need general support.

@jimmykarily
Copy link
Author

Since it's being used as a library, this bump is not necessarily required (already discussed this on another project) so feel free to keep it or close it.

@gammazero
Copy link
Contributor

Fixed by #748

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
need/triage Needs initial labeling and prioritization
Projects
None yet
Development

No branches or pull requests

2 participants