Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

vuln fix for CVE-2023-28840 #2

Merged
merged 1 commit into from
May 15, 2023

Conversation

czhujer
Copy link
Owner

@czhujer czhujer commented May 15, 2023

No description provided.

@czhujer
Copy link
Owner Author

czhujer commented May 15, 2023

copy from: chartmuseum#189

@czhujer czhujer merged commit 32ea124 into czhujer:main May 15, 2023
@leventyalcin
Copy link

Hi @czhujer,

Out of curiosity, are you planing to use helm-push from your own repository? If I'm not the only one who feels things are moving too slow on the original repo, I could take a similar approach at some point. That's a too big responsibility to take, however, it will be easier to progress I suppose.

Cheers,

@czhujer
Copy link
Owner Author

czhujer commented May 17, 2023

Hi @leventyalcin,

for now, probably i have to :)
Because I wanted use version from origin main, because there are fixed some CVEs.
But looks like bump version of cobra library's caused some issues chartmuseum#187.
And after i've send MR/PR with fix, I'm cherry picked also your's FIX :)

@leventyalcin
Copy link

I totally understand. I was going to do the same but I'm only trying to avoid that because of an approval processes I have to go through. The last time I had to ping org owners thorugh Twitter. However, I'm reluctant to do it regularly 🤷‍♂️

@czhujer
Copy link
Owner Author

czhujer commented May 20, 2023

Yes, we will see :)

@leventyalcin
Copy link

@czhujer Just to let you know, your PR and mines are merged and a new version released. 👍

@czhujer
Copy link
Owner Author

czhujer commented Jun 8, 2023

@leventyalcin yes, i've seen. thank you for info :)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants