Skip to content
This repository has been archived by the owner on Dec 13, 2023. It is now read-only.

Fix Security Vulnerability on xstream component #2517

Merged
merged 1 commit into from
Oct 21, 2021

Conversation

taoj-action
Copy link
Contributor

Signed-off-by: Tao Jiang taoj@vmware.com

Pull Request type

  • Bugfix
  • Feature
  • Refactoring (no functional changes, no api changes)
  • Build related changes
  • Other (please describe):

Changes in this PR

Describe the new behavior from this PR, and why it's needed

Some critical vulnerabilities exist in the XStream component used in Conductor.

Issue # 2505
#2505

Alternatives considered

Deprecate and discontinue support for DynoQueues

_Describe alternative implementation you have considered

This approach inlines with the conductor's roadmap. https://github.com/Netflix/conductor/wiki/Roadmap but it may take a longer time to implement.

@taoj-action
Copy link
Contributor Author

No critical and major vulnerability was found after the fix.

Screen Shot 2021-10-14 at 8 04 29 PM

@aravindanr aravindanr added the type: dependencies Pull requests that update a dependency file label Oct 18, 2021
Control transives depedency version by upgrading.

Signed-off-by: Tao Jiang <taoj@vmware.com>
@jxu-nflx jxu-nflx self-requested a review October 20, 2021 20:04
@taoj-action
Copy link
Contributor Author

@jxu-nflx Thanks for approving it. Could you please help merge it? Thanks!

@jxu-nflx jxu-nflx merged commit fea0c14 into Netflix:main Oct 21, 2021
@taoj-action taoj-action deleted the fix-vulnerability branch October 21, 2021 23:30
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
type: dependencies Pull requests that update a dependency file
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants