openyurtio / openyurt

OpenYurt - Extending your native Kubernetes to edge(project under CNCF)
https://openyurt.io
Apache License 2.0
1.69k stars 398 forks source link

fix: upgrade the version of runc to avoid security risk #1972

Closed qclc closed 4 months ago

qclc commented 5 months ago

What type of PR is this?

Uncomment only one /kind <> line, hit enter to put that in a new line, and remove leading whitespace from that line: /kind bug /kind documentation /kind enhancement /kind good-first-issue /kind feature /kind question /kind design /sig ai /sig iot /sig network /sig storage

What this PR does / why we need it:

The runc(1.1.5) package indirectly imported by openyurt has some security risks before version 1.1.11, so the minor version number of the runc package is upgraded to version 1.1.12.

For specific details of security risks, please refer to: summary

Which issue(s) this PR fixes:

Fixes #

Special notes for your reviewer:

Does this PR introduce a user-facing change?

other Note

codecov[bot] commented 5 months ago

Codecov Report

All modified and coverable lines are covered by tests :white_check_mark:

Project coverage is 53.05%. Comparing base (c589f8a) to head (5db754c).

Additional details and impacted files ```diff @@ Coverage Diff @@ ## master #1972 +/- ## ======================================= Coverage 53.05% 53.05% ======================================= Files 176 176 Lines 20944 20944 ======================================= Hits 11112 11112 Misses 8884 8884 Partials 948 948 ``` | [Flag](https://app.codecov.io/gh/openyurtio/openyurt/pull/1972/flags?src=pr&el=flags&utm_medium=referral&utm_source=github&utm_content=comment&utm_campaign=pr+comments&utm_term=openyurtio) | Coverage Δ | | |---|---|---| | [unittests](https://app.codecov.io/gh/openyurtio/openyurt/pull/1972/flags?src=pr&el=flag&utm_medium=referral&utm_source=github&utm_content=comment&utm_campaign=pr+comments&utm_term=openyurtio) | `53.05% <ø> (ø)` | | Flags with carried forward coverage won't be shown. [Click here](https://docs.codecov.io/docs/carryforward-flags?utm_medium=referral&utm_source=github&utm_content=comment&utm_campaign=pr+comments&utm_term=openyurtio#carryforward-flags-in-the-pull-request-comment) to find out more.

:umbrella: View full report in Codecov by Sentry.
:loudspeaker: Have feedback on the report? Share it here.

sonarcloud[bot] commented 4 months ago

Quality Gate Passed Quality Gate passed

Issues
0 New issues
0 Accepted issues

Measures
0 Security Hotspots
No data about Coverage
No data about Duplication

See analysis details on SonarCloud

Congrool commented 4 months ago

/lgtm /approve