-
Notifications
You must be signed in to change notification settings - Fork 422
NO-JIRA: Bump library-go to update selinux and x/crypto #2169
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Conversation
|
@ardaguclu: This pull request explicitly references no jira issue. DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. |
Walkthroughgo.mod dependency versions updated: core golang.org/x modules, OpenShift modules, opencontainers/selinux, various Kubernetes-related indirects; new indirect cyphar modules added and a replace mapping updated for github.com/openshift/library-go. No API or exported symbols changed. Changes
Estimated code review effort🎯 3 (Moderate) | ⏱️ ~20 minutes
✨ Finishing touches🧪 Generate unit tests (beta)
📜 Recent review detailsConfiguration used: Organization UI Review profile: CHILL Plan: Pro Cache: Disabled due to data retention organization setting Knowledge base: Disabled due to ⛔ Files ignored due to path filters (105)
📒 Files selected for processing (1)
🧰 Additional context used📓 Path-based instructions (1)**⚙️ CodeRabbit configuration file
Files:
🔇 Additional comments (2)
Comment |
|
/hold |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Actionable comments posted: 1
📜 Review details
Configuration used: Organization UI
Review profile: CHILL
Plan: Pro
Cache: Disabled due to data retention organization setting
Knowledge base: Disabled due to Reviews -> Disable Knowledge Base setting
⛔ Files ignored due to path filters (105)
go.sumis excluded by!**/*.sumvendor/cyphar.com/go-pathrs/.golangci.ymlis excluded by!vendor/**,!**/vendor/**vendor/cyphar.com/go-pathrs/COPYINGis excluded by!vendor/**,!**/vendor/**vendor/cyphar.com/go-pathrs/doc.gois excluded by!vendor/**,!**/vendor/**vendor/cyphar.com/go-pathrs/handle_linux.gois excluded by!vendor/**,!**/vendor/**vendor/cyphar.com/go-pathrs/internal/fdutils/fd_linux.gois excluded by!vendor/**,!**/vendor/**vendor/cyphar.com/go-pathrs/internal/libpathrs/error_unix.gois excluded by!vendor/**,!**/vendor/**vendor/cyphar.com/go-pathrs/internal/libpathrs/libpathrs_linux.gois excluded by!vendor/**,!**/vendor/**vendor/cyphar.com/go-pathrs/procfs/procfs_linux.gois excluded by!vendor/**,!**/vendor/**vendor/cyphar.com/go-pathrs/root_linux.gois excluded by!vendor/**,!**/vendor/**vendor/cyphar.com/go-pathrs/utils_linux.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/cyphar/filepath-securejoin/COPYING.mdis excluded by!vendor/**,!**/vendor/**vendor/github.com/cyphar/filepath-securejoin/LICENSE.BSDis excluded by!vendor/**,!**/vendor/**vendor/github.com/cyphar/filepath-securejoin/LICENSE.MPL-2.0is excluded by!vendor/**,!**/vendor/**vendor/github.com/cyphar/filepath-securejoin/internal/consts/consts.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/cyphar/filepath-securejoin/pathrs-lite/README.mdis excluded by!vendor/**,!**/vendor/**vendor/github.com/cyphar/filepath-securejoin/pathrs-lite/doc.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/cyphar/filepath-securejoin/pathrs-lite/internal/assert/assert.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/cyphar/filepath-securejoin/pathrs-lite/internal/errors_linux.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/cyphar/filepath-securejoin/pathrs-lite/internal/fd/at_linux.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/cyphar/filepath-securejoin/pathrs-lite/internal/fd/fd.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/cyphar/filepath-securejoin/pathrs-lite/internal/fd/fd_linux.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/cyphar/filepath-securejoin/pathrs-lite/internal/fd/mount_linux.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/cyphar/filepath-securejoin/pathrs-lite/internal/fd/openat2_linux.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/cyphar/filepath-securejoin/pathrs-lite/internal/gocompat/README.mdis excluded by!vendor/**,!**/vendor/**vendor/github.com/cyphar/filepath-securejoin/pathrs-lite/internal/gocompat/doc.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/cyphar/filepath-securejoin/pathrs-lite/internal/gocompat/gocompat_errors_go120.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/cyphar/filepath-securejoin/pathrs-lite/internal/gocompat/gocompat_errors_unsupported.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/cyphar/filepath-securejoin/pathrs-lite/internal/gocompat/gocompat_generics_go121.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/cyphar/filepath-securejoin/pathrs-lite/internal/gocompat/gocompat_generics_unsupported.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/cyphar/filepath-securejoin/pathrs-lite/internal/gopathrs/doc.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/cyphar/filepath-securejoin/pathrs-lite/internal/gopathrs/lookup_linux.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/cyphar/filepath-securejoin/pathrs-lite/internal/gopathrs/mkdir_linux.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/cyphar/filepath-securejoin/pathrs-lite/internal/gopathrs/open_linux.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/cyphar/filepath-securejoin/pathrs-lite/internal/gopathrs/openat2_linux.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/cyphar/filepath-securejoin/pathrs-lite/internal/kernelversion/kernel_linux.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/cyphar/filepath-securejoin/pathrs-lite/internal/linux/doc.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/cyphar/filepath-securejoin/pathrs-lite/internal/linux/mount_linux.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/cyphar/filepath-securejoin/pathrs-lite/internal/linux/openat2_linux.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/cyphar/filepath-securejoin/pathrs-lite/internal/procfs/procfs_linux.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/cyphar/filepath-securejoin/pathrs-lite/internal/procfs/procfs_lookup_linux.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/cyphar/filepath-securejoin/pathrs-lite/mkdir.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/cyphar/filepath-securejoin/pathrs-lite/mkdir_libpathrs.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/cyphar/filepath-securejoin/pathrs-lite/mkdir_purego.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/cyphar/filepath-securejoin/pathrs-lite/open.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/cyphar/filepath-securejoin/pathrs-lite/open_libpathrs.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/cyphar/filepath-securejoin/pathrs-lite/open_purego.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/cyphar/filepath-securejoin/pathrs-lite/procfs/procfs_libpathrs.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/cyphar/filepath-securejoin/pathrs-lite/procfs/procfs_purego.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/opencontainers/selinux/go-selinux/selinux.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/opencontainers/selinux/go-selinux/selinux_linux.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/opencontainers/selinux/go-selinux/selinux_stub.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/openshift/api/.golangci.yamlis excluded by!vendor/**,!**/vendor/**vendor/github.com/openshift/api/AGENTS.mdis excluded by!vendor/**,!**/vendor/**vendor/github.com/openshift/api/Makefileis excluded by!vendor/**,!**/vendor/**vendor/github.com/openshift/api/config/v1/types_cluster_version.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/openshift/api/config/v1/types_infrastructure.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/openshift/api/config/v1/zz_generated.featuregated-crd-manifests.yamlis excluded by!vendor/**,!**/vendor/**vendor/github.com/openshift/api/config/v1/zz_generated.swagger_doc_generated.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/openshift/api/envtest-releases.yamlis excluded by!vendor/**,!**/vendor/**vendor/github.com/openshift/api/features.mdis excluded by!vendor/**,!**/vendor/**vendor/github.com/openshift/api/features/features.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/openshift/api/machine/v1beta1/types_gcpprovider.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/openshift/api/machine/v1beta1/zz_generated.deepcopy.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/openshift/api/machine/v1beta1/zz_generated.swagger_doc_generated.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/openshift/api/machineconfiguration/v1/zz_generated.featuregated-crd-manifests.yamlis excluded by!vendor/**,!**/vendor/**vendor/github.com/openshift/api/operator/v1/types_csi_cluster_driver.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/openshift/library-go/pkg/crypto/crypto.gois excluded by!vendor/**,!**/vendor/**vendor/github.com/openshift/library-go/pkg/operator/certrotation/signer.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/crypto/openpgp/s2k/s2k.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/crypto/sha3/doc.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/crypto/sha3/hashes.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/crypto/sha3/hashes_noasm.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/crypto/sha3/keccakf_amd64.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/crypto/sha3/keccakf_amd64.sis excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/crypto/sha3/legacy_hash.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/crypto/sha3/legacy_keccakf.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/crypto/sha3/sha3_s390x.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/crypto/sha3/sha3_s390x.sis excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/crypto/sha3/shake.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/crypto/sha3/shake_noasm.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/net/context/context.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/net/http2/frame.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/net/http2/transport.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/net/http2/writesched.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/net/http2/writesched_priority_rfc7540.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/net/http2/writesched_priority_rfc9218.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sync/errgroup/errgroup.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/cpu/cpu.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/cpu/cpu_arm64.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/cpu/cpu_arm64.sis excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/cpu/cpu_gc_arm64.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/cpu/cpu_gccgo_arm64.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/cpu/cpu_netbsd_arm64.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/cpu/cpu_openbsd_arm64.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/unix/mkerrors.shis excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/unix/syscall_linux.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/unix/zerrors_linux.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/unix/zsyscall_linux.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/unix/ztypes_linux.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/windows/syscall_windows.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/windows/types_windows.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/sys/windows/zsyscall_windows.gois excluded by!vendor/**,!**/vendor/**vendor/golang.org/x/term/terminal.gois excluded by!vendor/**,!**/vendor/**vendor/modules.txtis excluded by!vendor/**,!**/vendor/**
📒 Files selected for processing (1)
go.mod
🧰 Additional context used
📓 Path-based instructions (1)
**
⚙️ CodeRabbit configuration file
-Focus on major issues impacting performance, readability, maintainability and security. Avoid nitpicks and avoid verbosity.
Files:
go.mod
🔇 Additional comments (2)
go.mod (2)
51-56: Verify Go standard library version updates for compatibility.Lines 51–56 update several Go standard library modules to newer minor/patch versions:
golang.org/x/cryptov0.43.0 → v0.45.0golang.org/x/netv0.46.0 → v0.47.0golang.org/x/syncv0.17.0 → v0.18.0golang.org/x/sysv0.37.0 → v0.38.0golang.org/x/termv0.36.0 → v0.37.0These version bumps are typically backward-compatible, but ensure the codebase has been tested against these versions and that no API changes or behavioral changes introduce regressions.
72-72: New indirect dependencies added.Lines 72 and 101 add two new indirect dependencies:
cyphar.com/go-pathrs v0.2.1github.com/cyphar/filepath-securejoin v0.6.0Verify that these are legitimate transitive dependencies pulled in by updated packages (likely
containers/imageor related dependencies) and not accidentally introduced.Also applies to: 101-101
bc97a18 to
e3e3bd2
Compare
|
/hold cancel |
|
/lgtm |
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: ardaguclu, ricardomaraschini The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
|
/retest |
|
@ardaguclu: The following tests failed, say
Full PR test history. Your PR dashboard. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here. |
|
/retest |
This PR bumps library-go to update selinux and x/crypto versions, in order to fix the vulnerabilities.