YaleUniversity / packer-plugin-goss

Goss Provisioner for Packer
MIT License
136 stars 45 forks source link

Bump packer-plugin-sdk to latest #64

Closed SanikaGawhane closed 1 year ago

SanikaGawhane commented 1 year ago

Current version of packer-plugin (v0.2.3) has an old go-getter dependency (v2.0.0) that has CVEs - 30323, 30322, 30321

Latest release of packer-plugin-sdk (v0.3.2) has an updated go-getter 2.1.0 that resolves these.

After this is bumped, a new tag will be needed to be included in the image-builder project.

SanikaGawhane commented 1 year ago

@fishnix @jimmidyson PTAL. Thanks.

SanikaGawhane commented 1 year ago

@fishnix @jimmidyson Just checking if you got a chance to look at this. Please let me know if there are any other folks that might be more relevant for this PR/cutting a new tag. Thanks again.

SanikaGawhane commented 1 year ago

Thank you, @jimmidyson. Who would be the right person to get this merged and cut a new tag with these changes?

btassone commented 1 year ago

@SanikaGawhane - I can do that for you. Were you looking to cut a pre release first or just a normal release?

SanikaGawhane commented 1 year ago

Hi @btassone. We need a new tag that includes changes merged with this PR. I'm not sure, what's the difference between pre release and a regular release. Please advise what you think would be the right approach for this. Thank you.

btassone commented 1 year ago

Sorry @SanikaGawhane ignore what I said. Was thinking of a different repository. Merging and cutting a new release v3.1.4 here in a moment.

SanikaGawhane commented 1 year ago

Thanks, @btassone! Appreciate your timely help with this.