Skip to content

Conversation

stevenhorsman
Copy link
Member

Bump url, reqwests and idna crates in order to move away from idna <1.0.3 and remediate CVE-2024-12224.

@stevenhorsman stevenhorsman changed the title versions: Bump idna crate to >= 1.0.4 versions: Bump idna crate to >= 1.0.3 Jul 4, 2025
@stevenhorsman stevenhorsman added the security Potential or actual security issue label Jul 7, 2025
Bump url, reqwests and idna crates in order to move away from
idna <1.0.3 and remediate CVE-2024-12224.

Signed-off-by: stevenhorsman <steven@uk.ibm.com>
Update expected error after url crate bump

Signed-off-by: stevenhorsman <steven@uk.ibm.com>
Copy link
Member

@fidencio fidencio left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm, thanks @stevenhorsman!

@fidencio fidencio merged commit 579d373 into kata-containers:main Jul 14, 2025
502 of 527 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
ok-to-test security Potential or actual security issue
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants