Skip to content

Conversation

@sylvainOL
Copy link
Contributor

Hello,
while reviewing security CVEs on our cluster with my security officer, we found 2 CVEs involved with cert manager webhook pdns:

CVE-2024-24790 on stdlib
CVE-2024-45337 on golang.org/x/crypto

I've made 3 commits:

  • one to bump go dependencies
  • one to bump go to 1.24.0
  • one to bump helm in tests

tests are passing, hope it'll help!

Signed-off-by: Sylvain Desbureaux <[email protected]>
Signed-off-by: Sylvain Desbureaux <[email protected]>
Signed-off-by: Sylvain Desbureaux <[email protected]>
@zachomedia
Copy link
Owner

Amazing, thank you! I've triggered the CI to get the green checkmark on the PR, and then I'll merge it and tag it up (I'm overdue on tagging the last dependency bump I did)

@zachomedia zachomedia self-assigned this Feb 18, 2025
@zachomedia zachomedia merged commit 0c44f13 into zachomedia:main Feb 18, 2025
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants