Skip to content

Commit

Permalink
bump up containerd to 1.6.36
Browse files Browse the repository at this point in the history
The current version 1.6.9 has known vulnerbilities,
and the minimum version fixing them is 1.6.26:

https://pkg.go.dev/github.com/containerd/[email protected]?tab=versions

I think we can just upgrade to the latest 1.6.36 release, which
will also remove the dependency on runc 1.1.2, as runc also
has vulnerbilities between 1.1.2 and 1.1.13.

Signed-off-by: Jin Dong <[email protected]>
  • Loading branch information
djdongjin committed Jan 4, 2025
1 parent ff86ae8 commit ddf06dc
Show file tree
Hide file tree
Showing 2 changed files with 34 additions and 39 deletions.
21 changes: 11 additions & 10 deletions plugins/v010-adapter/go.mod
Original file line number Diff line number Diff line change
Expand Up @@ -3,17 +3,18 @@ module github.com/containerd/nri/plugins/v010-adapter
go 1.21

require (
github.com/containerd/containerd v1.6.9
github.com/containerd/containerd v1.6.36
github.com/containerd/nri v0.6.1
github.com/opencontainers/runtime-spec v1.1.0
github.com/sirupsen/logrus v1.9.3
)

require (
github.com/Microsoft/go-winio v0.5.2 // indirect
github.com/Microsoft/hcsshim v0.9.4 // indirect
github.com/containerd/cgroups v1.0.3 // indirect
github.com/Microsoft/go-winio v0.5.3 // indirect
github.com/Microsoft/hcsshim v0.9.12 // indirect
github.com/containerd/cgroups v1.0.4 // indirect
github.com/containerd/continuity v0.3.0 // indirect
github.com/containerd/errdefs v0.1.0 // indirect
github.com/containerd/fifo v1.0.0 // indirect
github.com/containerd/log v0.1.0 // indirect
github.com/containerd/ttrpc v1.2.7 // indirect
Expand All @@ -22,16 +23,16 @@ require (
github.com/gogo/googleapis v1.4.0 // indirect
github.com/gogo/protobuf v1.3.2 // indirect
github.com/golang/groupcache v0.0.0-20210331224755-41bb18bfe9da // indirect
github.com/golang/protobuf v1.5.3 // indirect
github.com/google/uuid v1.3.0 // indirect
github.com/golang/protobuf v1.5.4 // indirect
github.com/google/uuid v1.3.1 // indirect
github.com/klauspost/compress v1.15.9 // indirect
github.com/knqyf263/go-plugin v0.8.1-0.20240827022226-114c6257e441 // indirect
github.com/moby/locker v1.0.1 // indirect
github.com/moby/sys/mountinfo v0.6.2 // indirect
github.com/moby/sys/signal v0.6.0 // indirect
github.com/moby/sys/user v0.1.0 // indirect
github.com/opencontainers/go-digest v1.0.0 // indirect
github.com/opencontainers/image-spec v1.0.3-0.20211202183452-c5a74bcca799 // indirect
github.com/opencontainers/runc v1.1.2 // indirect
github.com/opencontainers/image-spec v1.1.0 // indirect
github.com/opencontainers/selinux v1.10.2 // indirect
github.com/pkg/errors v0.9.1 // indirect
github.com/tetratelabs/wazero v1.8.2-0.20241030035603-dc08732e57d5 // indirect
Expand All @@ -40,8 +41,8 @@ require (
golang.org/x/sync v0.7.0 // indirect
golang.org/x/sys v0.21.0 // indirect
golang.org/x/text v0.15.0 // indirect
google.golang.org/genproto/googleapis/rpc v0.0.0-20230731190214-cbb8c96f2d6d // indirect
google.golang.org/grpc v1.57.1 // indirect
google.golang.org/genproto/googleapis/rpc v0.0.0-20231002182017-d307bd883b97 // indirect
google.golang.org/grpc v1.59.0 // indirect
google.golang.org/protobuf v1.34.1 // indirect
k8s.io/cri-api v0.25.3 // indirect
)
Expand Down
Loading

0 comments on commit ddf06dc

Please sign in to comment.