OCPBUGS-80539: Bump google.golang.org/grpc to v1.79.3#17
OCPBUGS-80539: Bump google.golang.org/grpc to v1.79.3#17ocp-sustaining-admins wants to merge 1 commit intoopenshift:release-4.20from
Conversation
|
@ocp-sustaining-admins: This pull request references Jira Issue OCPBUGS-80539, which is invalid:
Comment The bug has been updated to refer to the pull request using the external bug tracker. DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. |
|
Important Review skippedAuto reviews are limited based on label configuration. 🚫 Review skipped — only excluded labels are configured. (1)
Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Hi @ocp-sustaining-admins. Thanks for your PR. I'm waiting for a openshift member to verify that this patch is reasonable to test. If it is, they should reply with Regular contributors should join the org to skip this step. Once the patch is verified, the new status will be reflected by the I understand the commands that are listed here. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
|
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: ocp-sustaining-admins The full list of commands accepted by this bot can be found here. DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
c9d017f to
ee2b4b2
Compare
|
/ok-to-test |
|
@ocp-sustaining-admins: The following test failed, say
Full PR test history. Your PR dashboard. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here. |
|
Hi. Do we need this PR? |
|
Hi @racheljpg, The Openshift Sustaining team is still working on the ARC automation. There was an issue when this PR was created because it did not handle the fact that the actual vulnerability is in a subfolder. https://github.com/openshift/azure-service-operator/blob/release-4.20/v2/go.mod#L122 Due to the practical requirements of fixing CVEs across all versions of components within OCP we will automatically bump all packages contained in the repo, even if they are not the main entry point. We are working on a fix now and once resolved, we will re-run the automation which will update this PR. Secondarily we are also aware that some components require commit verification upstream. We are working to determine the best way to automate this. Please bare with us while we take advantage of this real world case and make adjustments to our automation. For now you can leave this PR to the Sustaining team. We will either make sure that it is valid, or will close it out if we are unable to arrive at a solution with the automation within our time constraints. |
This is an automated PR from the ARC system.
Go version used:
go1.24.13The commands used to generate this PR were:
A member of the Red Hat Openshift Sustaining Team will review the PR and take appropriate action.