Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update Cobra version to 1.2.1 #13571

Merged
merged 1 commit into from Jan 14, 2022
Merged

Conversation

yank1
Copy link

@yank1 yank1 commented Dec 29, 2021

Addresses CVE-2020-26160 related to github.com/dgrijalva/jwt-go.
And resolve the problem of circular dependency

Closes #13390
Refer to #13396

Signed-off-by: yankay kay.yan@daocloud.io

Signed-off-by: yankay <kay.yan@daocloud.io>
@yankay
Copy link
Contributor

yankay commented Jan 11, 2022

HI @ptabor ,How do you think about the PR.

@ptabor
Copy link
Contributor

ptabor commented Jan 12, 2022

LGTM if the test passes.

@ptabor ptabor merged commit f75549d into etcd-io:main Jan 14, 2022
yankay added a commit to yankay/etcd that referenced this pull request Mar 14, 2022
yankay added a commit to yankay/etcd that referenced this pull request Mar 14, 2022
yankay added a commit to yankay/etcd that referenced this pull request Mar 14, 2022
yankay added a commit to yankay/etcd that referenced this pull request Mar 14, 2022
yankay added a commit to yankay/etcd that referenced this pull request Mar 14, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Development

Successfully merging this pull request may close these issues.

Cobra upgrade: transitive dependency vulnerability
3 participants