Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump packer-plugin-sdk to latest #64

Merged

Conversation

SanikaGawhane
Copy link
Contributor

@SanikaGawhane SanikaGawhane commented Oct 17, 2022

Current version of packer-plugin (v0.2.3) has an old go-getter dependency (v2.0.0) that has CVEs - 30323, 30322, 30321

Latest release of packer-plugin-sdk (v0.3.2) has an updated go-getter 2.1.0 that resolves these.

After this is bumped, a new tag will be needed to be included in the image-builder project.

@SanikaGawhane
Copy link
Contributor Author

@fishnix @jimmidyson PTAL. Thanks.

@SanikaGawhane
Copy link
Contributor Author

@fishnix @jimmidyson Just checking if you got a chance to look at this. Please let me know if there are any other folks that might be more relevant for this PR/cutting a new tag. Thanks again.

@SanikaGawhane
Copy link
Contributor Author

Thank you, @jimmidyson.
Who would be the right person to get this merged and cut a new tag with these changes?

@btassone
Copy link
Contributor

@SanikaGawhane - I can do that for you. Were you looking to cut a pre release first or just a normal release?

@SanikaGawhane
Copy link
Contributor Author

Hi @btassone.
We need a new tag that includes changes merged with this PR.
I'm not sure, what's the difference between pre release and a regular release. Please advise what you think would be the right approach for this. Thank you.

@btassone
Copy link
Contributor

Sorry @SanikaGawhane ignore what I said. Was thinking of a different repository. Merging and cutting a new release v3.1.4 here in a moment.

@btassone btassone merged commit 5b2bf82 into YaleUniversity:master Oct 20, 2022
@SanikaGawhane
Copy link
Contributor Author

Thanks, @btassone! Appreciate your timely help with this.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants