kubernetes-sigs / cluster-proportional-autoscaler

Kubernetes Cluster Proportional Autoscaler Container
Apache License 2.0
637 stars 131 forks source link

Update version of google.golang.org/protobuf due to CVE-2024-24786 #220

Open nirnaymsft opened 3 months ago

nirnaymsft commented 3 months ago

Update version of google.golang.org/protobuf v1.31.0 to 1.33.0

Issue: golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of...

https://avd.aquasec.com/nvd/cve-2024-24786

nirnaymsft commented 3 months ago

Please approve PR https://github.com/kubernetes-sigs/cluster-proportional-autoscaler/pull/193 to resolve this issue.

k8s-triage-robot commented 5 days ago

The Kubernetes project currently lacks enough contributors to adequately respond to all issues.

This bot triages un-triaged issues according to the following rules:

You can:

Please send feedback to sig-contributor-experience at kubernetes/community.

/lifecycle stale