libopenstorage / stork

Stork - Storage Orchestration Runtime for Kubernetes
Apache License 2.0
392 stars 89 forks source link

pwx-38748: upgrade gcloud-sdk version to fix crc32 vuln #1837

Closed strivedi-px closed 2 months ago

strivedi-px commented 2 months ago

What type of PR is this?

security-fix

What this PR does / why we need it: Upgrades gcloud-sdk version to 489.0.0 to fix gcloud-crc32 binary vulnerability. Sample run on my private image: https://aetos.pwx.purestorage.com/security/Stork/24-3-0/2024-08-26-13-07-11-855359

Does this PR change a user-facing CRD or CLI?: Yes

Is a release note needed?: Yes

Does this change need to be cherry-picked to a release branch?: Yes, 24.3.0.