metal3-io / baremetal-operator

Bare metal host provisioning integration for Kubernetes
Apache License 2.0
570 stars 253 forks source link

:seedling: Bump docker/docker in test/ to v25.0.6 #1894

Closed mquhuy closed 1 month ago

mquhuy commented 1 month ago

Bump to fix this issue: https://osv.dev/vulnerability/GO-2024-3005

metal3-io-bot commented 1 month ago

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by: Once this PR has been reviewed and has the lgtm label, please assign lentzi90 for approval. For more information see the Kubernetes Code Review Process.

The full list of commands accepted by this bot can be found here.

Needs approval from an approver in each of these files: - **[OWNERS](https://github.com/metal3-io/baremetal-operator/blob/release-0.6/OWNERS)** Approvers can indicate their approval by writing `/approve` in a comment Approvers can cancel approval by writing `/approve cancel` in a comment
tuminoid commented 1 month ago

This is not going to work. Docker major versions are not compatible without code changes, hence I did not bump it earlier as we don't use the vulnerable functionality.

/hold