Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

deps Update module github.com/open-policy-agent/opa to v0.62.1 #293

Merged
merged 1 commit into from
Mar 7, 2024

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Mar 6, 2024

Mend Renovate

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
github.com/open-policy-agent/opa v0.62.0 -> v0.62.1 age adoption passing confidence

Release Notes

open-policy-agent/opa (github.com/open-policy-agent/opa)

v0.62.1

Compare Source

This is a security fix release for the fixes published in Go 1.22.1.

OPA servers using --authentication=tls would be affected: crafted malicious client certificates could cause a panic in the server.

Also, crafted server certificates could panic OPA's HTTP clients, in bundle plugin, status and decision logs; and http.send calls that verify TLS.

This is CVE-2024-24783 (https://pkg.go.dev/vuln/GO-2024-2598).

Note that there are other security fixes in this Golang release, but whether or not OPA is affected is harder to assess. An update is advised.

Miscellaneous

Configuration

📅 Schedule: Branch creation - "after 12pm every weekday,before 11am every weekday" in timezone America/New_York, Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate. View repository job log here.

Copy link

netlify bot commented Mar 6, 2024

Deploy Preview for lula-docs canceled.

Name Link
🔨 Latest commit f32b877
🔍 Latest deploy log https://app.netlify.com/sites/lula-docs/deploys/65e934e3f3113e0008878056

@renovate renovate bot force-pushed the renovate/github.com-open-policy-agent-opa-0.x branch from bd4f5e9 to 1e1dff3 Compare March 6, 2024 20:38
| datasource | package                          | from    | to      |
| ---------- | -------------------------------- | ------- | ------- |
| go         | github.com/open-policy-agent/opa | v0.62.0 | v0.62.1 |
@renovate renovate bot force-pushed the renovate/github.com-open-policy-agent-opa-0.x branch from 1e1dff3 to f32b877 Compare March 7, 2024 03:30
Copy link
Member

@brandtkeller brandtkeller left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Validated checksums against the go checksum db. Reviewed changes to the module source to review intent of the security fix release.

@brandtkeller brandtkeller merged commit 5e1049d into main Mar 7, 2024
7 checks passed
@brandtkeller brandtkeller deleted the renovate/github.com-open-policy-agent-opa-0.x branch March 7, 2024 23:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant