Skip to content
This repository has been archived by the owner on Feb 9, 2024. It is now read-only.

bump kubernetes to 1.19.15 for CVE-2021-25741 #2644

Merged
merged 1 commit into from
Sep 20, 2021

Conversation

knisbet
Copy link
Contributor

@knisbet knisbet commented Sep 17, 2021

Bump kubernetes to 1.19.15 to avoid CVE-2021-25741. See https://groups.google.com/g/kubernetes-announce/c/-e9OlTcED5E for more information from the Kubernetes project.

Planet PR gravitational/planet#863

@knisbet knisbet requested review from a team, wadells and bernardjkim September 17, 2021 21:29
Copy link
Contributor

@wadells wadells left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM.

Please link your related planet PR for tracking purposes. 😄

@@ -46,7 +46,7 @@ RELEASE_OUT ?=
TELEPORT_TAG = 3.2.17
# TELEPORT_REPOTAG adapts TELEPORT_TAG to the teleport tagging scheme
TELEPORT_REPOTAG := v$(TELEPORT_TAG)
PLANET_TAG := 8.0.4-$(K8S_VER_SUFFIX)
PLANET_TAG := 8.0.6-$(K8S_VER_SUFFIX)
Copy link
Contributor

@wadells wadells Sep 17, 2021

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks like this is also introducing some unrelated changes from 8.0.5-11912 / gravitational/planet#859. I don't anticipate any risk here, but I also haven't reviewed that code myself.

@knisbet knisbet merged commit af9be8c into version/8.0.x Sep 20, 2021
@knisbet knisbet deleted the kevin/8.0.x/bump-kubernetes-for-cve branch September 20, 2021 00:22
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants