opendatahub-io / modelmesh-serving

Controller for ModelMesh
Apache License 2.0
3 stars 32 forks source link

Fixes vulnerabilities on the otelhttp dependency #263

Closed Jooho closed 10 months ago

Jooho commented 10 months ago

Motivation

chore: Fixes the following vulnerabilities in the go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp dependency:

CVE-2022-21698 / CVE-2023-45142: Allocation of Resources Without Limits or Throttling

PR checklist

Checklist items below are applicable for development targeted to both fast and stable branches/tags

Checklist items below are applicable for development targeted to both fast and stable branches/tags

openshift-ci[bot] commented 10 months ago

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: Jooho

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Needs approval from an approver in each of these files: - ~~[OWNERS](https://github.com/opendatahub-io/modelmesh-serving/blob/release-0.11.1/OWNERS)~~ [Jooho] Approvers can indicate their approval by writing `/approve` in a comment Approvers can cancel approval by writing `/approve cancel` in a comment
Jooho commented 10 months ago

it turned out that the build issue only happened with release-0.11.1 so I created another PR (https://github.com/opendatahub-io/modelmesh-serving/pull/268)

Jooho commented 10 months ago

/retest