chore: upgrade redis to 7.0.8 to avoid several CVEs#12627
chore: upgrade redis to 7.0.8 to avoid several CVEs#12627crenshaw-dev merged 1 commit intoargoproj:masterfrom
Conversation
Signed-off-by: Justin Marquis <34fathombelow@protonmail.com>
Codecov ReportBase: 47.78% // Head: 47.78% // No change to project coverage 👍
Additional details and impacted files@@ Coverage Diff @@
## master #12627 +/- ##
=======================================
Coverage 47.78% 47.78%
=======================================
Files 246 246
Lines 41944 41944
=======================================
Hits 20045 20045
Misses 19898 19898
Partials 2001 2001 Help us with your feedback. Take ten seconds to tell us how you rate us. Have a feature suggestion? Share it here. ☔ View full report at Codecov. |
|
/cherry-pick release-2.6 |
|
/cherry-pick release-2.5 |
|
/cherry-pick release-2.4 |
|
Cherry-pick failed with |
|
Cherry-pick failed with |
|
Cherry-pick failed with |
|
Bad bot. |
Signed-off-by: Justin Marquis <34fathombelow@protonmail.com>
Signed-off-by: Justin Marquis <34fathombelow@protonmail.com>
Signed-off-by: Justin Marquis <34fathombelow@protonmail.com>
|
Cherry-picked onto release-2.6 for 2.6.4, release-2.5 for 2.5.13, and release-2.4 for 2.4.25. |
Signed-off-by: Justin Marquis <34fathombelow@protonmail.com> Signed-off-by: Yi Cai <yicai@redhat.com>
Signed-off-by: Justin Marquis <34fathombelow@protonmail.com> Signed-off-by: rumstead <37445536+rumstead@users.noreply.github.com>
* Upgrade qs to avoid CVE-2022-24999 Signed-off-by: Yi Cai <yicai@redhat.com> * chore: upgrade haproxy to 2.6.9 to avoid multiple CVEs (#12628) Signed-off-by: Justin Marquis <34fathombelow@protonmail.com> Signed-off-by: Yi Cai <yicai@redhat.com> * chore: upgrade redis to 7.0.8 to avoid several CVEs (#12627) Signed-off-by: Justin Marquis <34fathombelow@protonmail.com> Signed-off-by: Yi Cai <yicai@redhat.com> * [Bot] docs: Update Snyk reports (#12660) Signed-off-by: CI <ci@argoproj.com> Co-authored-by: CI <ci@argoproj.com> Signed-off-by: Yi Cai <yicai@redhat.com> * Upgrade qs to avoid cve-2022-24999 Signed-off-by: Yi Cai <yicai@redhat.com> --------- Signed-off-by: Yi Cai <yicai@redhat.com> Signed-off-by: Justin Marquis <34fathombelow@protonmail.com> Signed-off-by: CI <ci@argoproj.com> Co-authored-by: Justin Marquis <34fathombelow@protonmail.com> Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: CI <ci@argoproj.com>
Signed-off-by: Justin Marquis <34fathombelow@protonmail.com>
* Upgrade qs to avoid CVE-2022-24999 Signed-off-by: Yi Cai <yicai@redhat.com> * chore: upgrade haproxy to 2.6.9 to avoid multiple CVEs (argoproj#12628) Signed-off-by: Justin Marquis <34fathombelow@protonmail.com> Signed-off-by: Yi Cai <yicai@redhat.com> * chore: upgrade redis to 7.0.8 to avoid several CVEs (argoproj#12627) Signed-off-by: Justin Marquis <34fathombelow@protonmail.com> Signed-off-by: Yi Cai <yicai@redhat.com> * [Bot] docs: Update Snyk reports (argoproj#12660) Signed-off-by: CI <ci@argoproj.com> Co-authored-by: CI <ci@argoproj.com> Signed-off-by: Yi Cai <yicai@redhat.com> * Upgrade qs to avoid cve-2022-24999 Signed-off-by: Yi Cai <yicai@redhat.com> --------- Signed-off-by: Yi Cai <yicai@redhat.com> Signed-off-by: Justin Marquis <34fathombelow@protonmail.com> Signed-off-by: CI <ci@argoproj.com> Co-authored-by: Justin Marquis <34fathombelow@protonmail.com> Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: CI <ci@argoproj.com>
This PR fixes several CVEs found in the recent Snyk Scan for Redis.
CVE-2022-4450
CVE-2022-4450
CVE-2023-0216
CVE-2023-0217
CVE-2023-0286
CVE-2023-0286