puppetlabs / puppet-runtime

runtime dependencies for Vanagon projects
Apache License 2.0
5 stars 88 forks source link

Upgrade agent-runtime#main's Curl to 8.10.0 #912

Closed cthorn42 closed 4 weeks ago

cthorn42 commented 2 months ago

Curl announced a new version 8.10.0, that fixes a newly announced CVE: CVE-2024-8096. Our currently released puppet-agent in the 8.x stream 8.9.0, is using Curl 8.9.1, https://github.com/puppetlabs/puppet-runtime/blob/202409030/configs/components/curl.rb#L9-L10. We should update that to the latest version.

github-actions[bot] commented 2 months ago

Migrated issue to PA-6962