Skip to content

DFBUGS-1996: [release-4.19] CVE-2025-22870 csi-addons: golang.org/x/net v0.32.0 #280

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Conversation

openshift-cherrypick-robot

This is an automated cherry-pick of #279

/assign iPraveenParihar

This commit addresses the CVE-2025-22870.

url: GHSA-qxp5-gwg8-xv66
fix resolution: upgrade to version > v0.36.0

Signed-off-by: Praveen M <[email protected]>
This commit addresses the CVE-2025-22870.

url: GHSA-qxp5-gwg8-xv66
fix resolution: upgrade to version > v0.36.0

Signed-off-by: Praveen M <[email protected]>
@iPraveenParihar
Copy link
Member

iPraveenParihar commented Apr 11, 2025

/retitle DFBUGS-1996: [release-4.19] CVE-2025-22870 csi-addons: golang.org/x/net v0.32.0

@openshift-ci openshift-ci bot changed the title [release-4.19] Syncing latest changes from upstream main for kubernetes-csi-addons DFBUGS-1996: [release-4.19] CVE-2025-22870 csi-addons: golang.org/x/net v0.32.0 Apr 11, 2025
@openshift-ci-robot
Copy link

openshift-ci-robot commented Apr 11, 2025

@openshift-cherrypick-robot: This pull request references [Jira Issue DFBUGS-1996](https://issues.redhat.com//browse/DFBUGS-1996), which is invalid:

  • expected the bug to target the "odf-4.19" version, but no target version was set

Comment /jira refresh to re-evaluate validity if changes to the Jira bug are made, or edit the title of this pull request to link to a different bug.

In response to this:

This is an automated cherry-pick of #279

/assign iPraveenParihar

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@iPraveenParihar
Copy link
Member

/jira refresh

@openshift-ci-robot
Copy link

openshift-ci-robot commented Apr 11, 2025

@iPraveenParihar: This pull request references [Jira Issue DFBUGS-1996](https://issues.redhat.com//browse/DFBUGS-1996), which is invalid:

  • expected the bug to target the "odf-4.19" version, but no target version was set

Comment /jira refresh to re-evaluate validity if changes to the Jira bug are made, or edit the title of this pull request to link to a different bug.

In response to this:

/jira refresh

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@iPraveenParihar
Copy link
Member

/jira refresh

@openshift-ci-robot
Copy link

openshift-ci-robot commented Apr 11, 2025

@iPraveenParihar: This pull request references [Jira Issue DFBUGS-1996](https://issues.redhat.com//browse/DFBUGS-1996), which is invalid:

  • expected the bug to target the "odf-4.19" version, but no target version was set

Comment /jira refresh to re-evaluate validity if changes to the Jira bug are made, or edit the title of this pull request to link to a different bug.

In response to this:

/jira refresh

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@iPraveenParihar
Copy link
Member

/jira refresh

@openshift-ci-robot openshift-ci-robot added jira/valid-bug Indicates that the referenced jira bug is valid for the branch this PR is targeting and removed jira/invalid-bug labels Apr 11, 2025
@openshift-ci-robot
Copy link

openshift-ci-robot commented Apr 11, 2025

@iPraveenParihar: This pull request references [Jira Issue DFBUGS-1996](https://issues.redhat.com//browse/DFBUGS-1996), which is valid. The bug has been moved to the POST state.

3 validation(s) were run on this bug
  • bug is open, matching expected state (open)
  • bug target version (odf-4.19) matches configured target version for branch (odf-4.19)
  • bug is in the state ASSIGNED, which is one of the valid states (NEW, ASSIGNED, POST)

Requesting review from QA contact:
/cc @nehaberry

In response to this:

/jira refresh

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

Copy link

openshift-ci bot commented Apr 11, 2025

@openshift-ci-robot: GitHub didn't allow me to request PR reviews from the following users: nehaberry.

Note that only red-hat-storage members and repo collaborators can review this PR, and authors cannot review their own PRs.

In response to this:

@iPraveenParihar: This pull request references [Jira Issue DFBUGS-1996](https://issues.redhat.com//browse/DFBUGS-1996), which is valid. The bug has been moved to the POST state.

3 validation(s) were run on this bug
  • bug is open, matching expected state (open)
  • bug target version (odf-4.19) matches configured target version for branch (odf-4.19)
  • bug is in the state ASSIGNED, which is one of the valid states (NEW, ASSIGNED, POST)

Requesting review from QA contact:
/cc @nehaberry

In response to this:

/jira refresh

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@nixpanic
Copy link
Member

/lgtm

Copy link

openshift-ci bot commented Apr 14, 2025

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: nixpanic, openshift-cherrypick-robot

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-merge-bot openshift-merge-bot bot merged commit 9e3b18a into red-hat-storage:release-4.19 Apr 14, 2025
12 of 13 checks passed
@openshift-ci-robot
Copy link

openshift-ci-robot commented Apr 14, 2025

@openshift-cherrypick-robot: [Jira Issue DFBUGS-1996](https://issues.redhat.com//browse/DFBUGS-1996): All pull requests linked via external trackers have merged:

[Jira Issue DFBUGS-1996](https://issues.redhat.com//browse/DFBUGS-1996) has been moved to the MODIFIED state.

In response to this:

This is an automated cherry-pick of #279

/assign iPraveenParihar

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
approved jira/valid-bug Indicates that the referenced jira bug is valid for the branch this PR is targeting jira/valid-reference lgtm
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants