Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade go modules to version which has CVE fixes #1615

Closed
wants to merge 1 commit into from

Conversation

noorul
Copy link

@noorul noorul commented Aug 8, 2022

Fixes #1614

@noorul noorul requested a review from a team August 8, 2022 06:44
@hashicorp-cla
Copy link

CLA assistant check

Thank you for your submission! We require that all contributors sign our Contributor License Agreement ("CLA") before we can accept the contribution. Read and sign the agreement

Learn more about why HashiCorp requires a CLA and what the CLA includes

Have you signed the CLA already but the status is still pending? Recheck it.

@eikenb
Copy link
Contributor

eikenb commented Aug 11, 2022

Hey @noorul, thanks for the issue and PR!

Dependabot is supposed to pick these things up... not sure why it missed this one. Thanks for reporting/fixing it.

That failure is due to a changed error message in the latest consul release. If you wouldn't mind rebasing on HEAD and re-pushing this it should fix that and allow the CI testing to pass.

@noorul
Copy link
Author

noorul commented Aug 12, 2022

@eikenb rebased

@eikenb
Copy link
Contributor

eikenb commented Aug 12, 2022

Thanks @noorul !

@noorul
Copy link
Author

noorul commented Aug 12, 2022

@eikenb Is CLA required for merge?

@eikenb
Copy link
Contributor

eikenb commented Aug 12, 2022

@noorul ..

@eikenb Is CLA required for merge?

Yes. I'm afraid it's required by my company.

@eikenb
Copy link
Contributor

eikenb commented Aug 12, 2022

Dependabot is supposed to pick these things up... not sure why it missed this one. Thanks for reporting/fixing it.

I see why dependabot didn't pick it up... I haven't enabled dependabot in this repo yet. 🤦

@noorul
Copy link
Author

noorul commented Aug 12, 2022

@eikenb Can you enable dependabot? I will be happy to discard this patch as I need to do some paper work to sign CLA.

@eikenb
Copy link
Contributor

eikenb commented Aug 12, 2022

I'll be happy to do that @noorul, I just like to use contributors submissions whenever possible. I'll work on getting dependabot enabled and making sure everything is up to date and happy. If you'd like to go that way please close this PR but leave the issue open. I should be able to mark it resolved in the Dependabot PR.

Thanks!

@eikenb
Copy link
Contributor

eikenb commented Aug 12, 2022

I have dependabot doing it's thing and am pretty sure I got this fixed with #1622. I'm still working on a few other dependabot updates but I'm going to go ahead and close this. Thanks again!

@eikenb eikenb closed this Aug 12, 2022
@noorul
Copy link
Author

noorul commented Aug 13, 2022

@eikenb Great! Thank you!

@noorul
Copy link
Author

noorul commented Aug 13, 2022

@eikenb Can we make a release?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

trivy scanner is reporting CVEs
3 participants