-
Notifications
You must be signed in to change notification settings - Fork 85
chore: update gopkg.in/yaml.v3 to v3.0.1 in tensorboard-controller #795
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
chore: update gopkg.in/yaml.v3 to v3.0.1 in tensorboard-controller #795
Conversation
andyatmiami
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
@asaadbalum - thanks for raising this! apologies in delay on turning attention to this - can you do the following before I test/approve?
- Rebase this PR on the latest of
notebooks-v1branch so I can test it in conjunction with other dependency updates that have been merged - Update
go.modto specify1.24.12(the latest minor version of1.24)
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
@asaadbalum - thanks for raising this! I realize this is a wildly trivial change - but just to be safe/proper - can you rebase this PR on the latest of notebooks-v1 branch so I can test it in conjunction with other dependency updates that have been merged
ℹ️ Please note you only need to rebase now - as forewarned in this comment - I got another PR merged that updated the go.mod
THANKS!
Update gopkg.in/yaml.v3 from v3.0.0-20210107192922-496545a6307b to v3.0.1 to fix: - CVE-2022-28948 Testing performed: - go mod tidy - completed successfully - go vet ./... - no issues found - make build - controller builds cleanly - make test - all tests pass Part of: kubeflow#781 Signed-off-by: Asaad Balum <asaad.balum@gmail.com>
a8dd75a to
69741d8
Compare
Hi @andyatmiami , done! Rebased on the latest notebooks-v1. Ready for your review when you get a chance. Thanks! |
|
/ok-to-test |
andyatmiami
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
/lgtm
thanks @asaadbalum for this contribution.
i independently confirmed the verification checks performed by the PR author are reproducible and valid.
furthermore, this is only a patch bump - and the only code change included here was a single bug fix for a very specific "bad input". as such - there is essentially no risk to adopting this code.
also worth noting a similar PR for notebook-controller was previously reviewed and merged.
|
/approve |
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: thesuperzapper The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
Description
Update
gopkg.in/yaml.v3from v3.0.0-20210107192922-496545a6307b to v3.0.1 in the tensorboard-controller to fix security vulnerabilities.CVEs Fixed:
Related Issue: Closes #781 (PR 5)
Changes
Updated dependencies in
components/tensorboard-controller/go.mod:gopkg.in/yaml.v3Testing
Local Build & Tests
go mod tidygo vet ./...make buildmake testCVE Verification (Trivy Scan)
Acceptance Criteria
go mod tidyto ensure dependencies are cleanmake buildto build the controllerSigned-off-by: Asaad Balum asaad.balum@gmail.com