Skip to content

Conversation

stevenhorsman
Copy link
Member

@stevenhorsman stevenhorsman commented Apr 28, 2025

Various high rust create bumps to fix high severity security alerts

@stevenhorsman stevenhorsman added security Potential or actual security issue ok-to-test labels Apr 28, 2025
@katacontainersbot katacontainersbot added the size/huge Largest and most complex task (probably needs breaking into small pieces) label Apr 28, 2025
Ensure that all the versions of mio we use are at
least 0.8.11 to remediate CVE-2024-27308

Signed-off-by: stevenhorsman <steven@uk.ibm.com>
Bump hashbrown to >= 0.15.1 to remediate the high severity
security alert that was in v0.15.0

Signed-off-by: stevenhorsman <steven@uk.ibm.com>
Bump rustls version to > 0.21.11 to remediate
high severity CVE-2024-32650

Signed-off-by: stevenhorsman <steven@uk.ibm.com>
@stevenhorsman stevenhorsman force-pushed the high-severity-security-bumps-april-25 branch from 23880fb to c938c75 Compare April 28, 2025 13:56
@stevenhorsman stevenhorsman changed the title High severity security bumps april 25 rust: High severity security bumps april 25 Apr 29, 2025
Copy link
Member

@fidencio fidencio left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm, thanks @stevenhorsman!

@fidencio fidencio merged commit a9893e8 into kata-containers:main Apr 29, 2025
660 of 686 checks passed
@stevenhorsman stevenhorsman deleted the high-severity-security-bumps-april-25 branch April 29, 2025 12:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
ok-to-test security Potential or actual security issue size/huge Largest and most complex task (probably needs breaking into small pieces)
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants