Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump lxml from 4.6.5 to 4.9.1 in /src/sonic-config-engine #14011

Merged
merged 2 commits into from
Mar 1, 2023

Conversation

xumia
Copy link
Collaborator

@xumia xumia commented Feb 28, 2023

Why I did it

It is to fix the security alert CVE-2022-2309, see https://security-tracker.debian.org/tracker/CVE-2022-2309
The fix has already merged in master, See detail in PR #11366

How I did it

Upgrade version to 4.9.1

How to verify it

Which release branch to backport (provide reason below if selected)

  • 201811
  • 201911
  • 202006
  • 202012
  • 202106
  • 202111
  • 202205
  • 202211

Description for the changelog

Ensure to add label/tag for the feature raised. example - PR#2174 under sonic-utilities repo. where, Generic Config and Update feature has been labelled as GCU.

Link to config_db schema for YANG module changes

A picture of a cute animal (not mandatory but encouraged)

@xumia xumia requested a review from lguohan as a code owner February 28, 2023 09:59
@linux-foundation-easycla
Copy link

linux-foundation-easycla bot commented Feb 28, 2023

CLA Signed

The committers listed above are authorized under a signed CLA.

@xumia
Copy link
Collaborator Author

xumia commented Feb 28, 2023

/easycla

@xumia xumia changed the title [PR:11366] Bump lxml from 4.6.5 to 4.9.1 in /src/sonic-config-engine Bump lxml from 4.6.5 to 4.9.1 in /src/sonic-config-engine Feb 28, 2023
@xumia
Copy link
Collaborator Author

xumia commented Feb 28, 2023

/azp run Azure.sonic-buildimage

@azure-pipelines
Copy link

Azure Pipelines successfully started running 1 pipeline(s).

@xumia xumia enabled auto-merge (squash) March 1, 2023 05:09
@xumia xumia merged commit b8ef3c0 into sonic-net:202205 Mar 1, 2023
@xumia xumia deleted the fix-lxml-202205 branch March 1, 2023 08:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants