Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Dependency update - Golang 1.15.7 #1851

Closed
17 of 21 tasks
justaugustus opened this issue Jan 15, 2021 · 4 comments
Closed
17 of 21 tasks

Dependency update - Golang 1.15.7 #1851

justaugustus opened this issue Jan 15, 2021 · 4 comments
Assignees
Labels
area/dependency Issues or PRs related to dependency changes area/release-eng Issues or PRs related to the Release Engineering subproject kind/feature Categorizes issue or PR as related to a new feature. priority/critical-urgent Highest priority. Must be actively worked on as someone's top priority right now. sig/release Categorizes an issue or PR as relevant to SIG Release.
Milestone

Comments

@justaugustus
Copy link
Member

justaugustus commented Jan 15, 2021

Tracking info

Golang 1.15.7 is a security release scheduled to come out on 1/19.
@kubernetes/release-engineering
/assign @ameukam @cpanato
cc: @RobertKielty

Link to any previous tracking issue:

Golang mailing list announcement: https://groups.google.com/g/golang-announce/c/KvrRblbXp_w, https://groups.google.com/g/golang-announce/c/mperVMGa98w

SIG Release Slack thread: https://kubernetes.slack.com/archives/C2C40FMNF/p1610736817029800

Work items for gox.y.z

During kube-cross image promotion

After kube-cross image promotion

After kubernetes/kubernetes has been updated

Cherry picks

Follow-up items

  • Ensure the Golang issue template is updated with any new requirements

/assign
cc: @kubernetes/release-engineering

@justaugustus justaugustus added kind/feature Categorizes issue or PR as related to a new feature. sig/release Categorizes an issue or PR as relevant to SIG Release. area/release-eng Issues or PRs related to the Release Engineering subproject area/dependency Issues or PRs related to dependency changes labels Jan 15, 2021
@justaugustus justaugustus added this to the v1.21 milestone Jan 15, 2021
@justaugustus justaugustus added the priority/critical-urgent Highest priority. Must be actively worked on as someone's top priority right now. label Jan 15, 2021
@justaugustus justaugustus removed their assignment Jan 15, 2021
@brandond
Copy link

New releases are out: https://groups.google.com/g/golang-announce/c/mperVMGa98w

  • cmd/go: packages using cgo can cause arbitrary code execution at build time
  • crypto/elliptic: incorrect operations on the P-224 curve

@justaugustus
Copy link
Member Author

We've started up with this update in #1857, but just noting here that these security updates should be minimally impactful to kubernetes/kubernetes, as @brandond suggested in Slack.

@justaugustus
Copy link
Member Author

Golang 1.15.8 has been released.
We'll be tracking any remaining work here: #1895

/close

@k8s-ci-robot
Copy link
Contributor

@justaugustus: Closing this issue.

In response to this:

Golang 1.15.8 has been released.
We'll be tracking any remaining work here: #1895

/close

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
area/dependency Issues or PRs related to dependency changes area/release-eng Issues or PRs related to the Release Engineering subproject kind/feature Categorizes issue or PR as related to a new feature. priority/critical-urgent Highest priority. Must be actively worked on as someone's top priority right now. sig/release Categorizes an issue or PR as relevant to SIG Release.
Projects
None yet
Development

No branches or pull requests

5 participants