-
Notifications
You must be signed in to change notification settings - Fork 34
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
chore(deps): update module kubevirt.io/kubevirt to v1.2.1 [security] (release-v0.17) #511
Conversation
Signed-off-by: null <[email protected]>
ℹ Artifact update noticeFile name: modules/create-vm/go.modIn order to perform the update(s) described in the table above, Renovate ran the
Details:
|
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: redhat-renovate-bot The full list of commands accepted by this bot can be found here.
Needs approval from an approver in each of these files:
Approvers can indicate their approval by writing |
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: The full list of commands accepted by this bot can be found here.
Needs approval from an approver in each of these files:
Approvers can indicate their approval by writing |
@redhat-renovate-bot: The following tests failed, say
Full PR test history. Your PR dashboard. Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here. |
/close |
@ksimon1: Closed this PR. In response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
1 similar comment
@ksimon1: Closed this PR. In response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
Renovate Ignore NotificationBecause you closed this PR without merging, Renovate will ignore this update ( If you accidentally closed this PR, or if you changed your mind: rename this PR to get a fresh replacement PR. |
This PR contains the following updates:
v1.1.0
->v1.2.1
KubeVirt NULL pointer dereference flaw
CVE-2024-31420 / GHSA-vjhf-6xfr-5p9g / GO-2024-2688
More information
Details
A NULL pointer dereference flaw was found in KubeVirt. This flaw allows an attacker who has access to a virtual machine guest on a node with DownwardMetrics enabled to cause a denial of service by issuing a high number of calls to vm-dump-metrics --virtio and then deleting the virtual machine.
Severity
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
References
This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).
kubevirt allows a local attacker to execute arbitrary code via a crafted command
CVE-2024-33394 / GHSA-4q63-mr2m-57hf / GO-2024-2816
More information
Details
An issue in kubevirt kubevirt v1.2.0 and before allows a local attacker to execute arbitrary code via a crafted command to get the token component.
Severity
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
References
This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).
Release Notes
kubevirt/kubevirt (kubevirt.io/kubevirt)
v1.2.1
Compare Source
tag v1.2.1
Tagger: Antonio Cardace [email protected]
This release follows v1.2.0 and consists of 288 changes, contributed by 31 people, leading to 423 files changed, 13593 insertions(+), 11123 deletions(-).
The source code and selected binaries are available for download at: https://github.com/kubevirt/kubevirt/releases/tag/v1.2.1.
The primary release artifact of KubeVirt is the git tree. The release tag is
signed and can be verified using
git tag -v v1.2.1
.Pre-built containers are published on Quay and can be viewed at: https://quay.io/kubevirt/.
Notable changes
VirtualMachines
referencing an instance type are now allowed when theLiveUpdate
feature is enabled and will trigger theRestartRequired
condition if the reference within theVirtualMachine
is changed.kubevirt_vmi_phase_count
metric labelspasst
custom CNI binary statically, for thepasst
network binding plugin.kubevirt.io/ksm-enabled
node label to true if the ksm is managed by KubeVirt, instead of reflect the actual ksm value.Contributors
31 people contributed to this release:
112 fossedihelm [email protected]
22 Luboslav Pivarc [email protected]
12 Shelly Kagan [email protected]
8 Antonio Cardace [email protected]
6 Alvaro Romero [email protected]
5 João Vilaça [email protected]
4 Alice Frosi [email protected]
4 Assaf Admi [email protected]
4 Dharmit Shah [email protected]
4 Jed Lejosne [email protected]
4 Lee Yarwood [email protected]
3 Alex Kalenyuk [email protected]
3 Felix Matouschek [email protected]
3 Michael Henriksen [email protected]
3 avlitman [email protected]
3 bmordeha [email protected]
2 Brian Carey [email protected]
2 Javier Cano Cano [email protected]
2 Ram Lavi [email protected]
2 Vicente Cheng [email protected]
2 howard zhang [email protected]
1 Alay Patel [email protected]
1 Andrea Bolognani [email protected]
1 Andrej Krejcir [email protected]
1 Daniel Hiller [email protected]
1 Edu Gómez Escandell [email protected]
1 Edward Haas [email protected]
1 Orel Misan [email protected]
1 Shahaf Bahar [email protected]
Additional Resources
-----BEGIN PGP SIGNATURE-----
iQJIBAABCAAyFiEEL3WFe2eU+K2zCASGa/gKvUPjd9MFAmZVlX8UHGFjYXJkYWNl
QHJlZGhhdC5jb20ACgkQa/gKvUPjd9PHcg/9GKOBdiJvG4qKA/fLOvTyJrhFIoli
S2OSnpEOEtQq2AnFrgQD8cIgpX9WahWYjKL841rbxmvOAKAuw868913/Y36R75Le
xuyDVuN2dFdblCcx7oFw2USPWeThVqG283E+qhss+GHVuIFXGHatFYaI966QI9Xr
qyNIj+hnjyLZsaq8CWowSlIWF73leRfj1csw5XkbcWU4rAgDzKHLJoYQeX3Ekkma
rhn0NwYJi4jYHRxFzPhDGXwVn1ItwwtutyWQj1EnIxt04XojxZ8pyHJ6dBv96Hwc
3bo68aG9JmGI9P7bs7+5wbMlMFdHZVrSc44JxXcv6N6D1OVWQPJfSkFVKAMhHxZ9
vycFdBJ/1p3T4gu9loM063syw98L4UDBMmCZgfunn0gdgie9OsFTzVaFvi1brQ7E
dMfvr1oj8t1TOWZo71rBIDWULlwryMS9NWsVT84CteTTaVOEUva02UIf6l7CV9oq
DBax71hCK7vLGqBFT4evu8g9TNtmK9LArHVBeMwe16qXVlIyIqVeujBmLVr7Qly3
X6F96i+HqaUWyCRceTX1uOhD/r9AjghHzFJwDQX2C9+c3zFI/9/cy2ajwNemEHgx
X1xf9vi17bn1HT+oRRoH+slf9JdHFW0T2pFvBcwNhakyaN45gG6k4K4nGGKNrw8U
MDze3ObziJMJeuQ=
=gs80
-----END PGP SIGNATURE-----
v1.2.0
Compare Source
tag v1.2.0
Tagger: Antonio Cardace [email protected]
This release follows v1.1.1 and consists of 822 changes, contributed by 65 people, leading to 1234 files changed, 46897 insertions(+), 22403 deletions(-).
v1.2.0 is a promotion of release candidate v1.2.0-rc.1 which was originally published 2024-02-26
The source code and selected binaries are available for download at: https://github.com/kubevirt/kubevirt/releases/tag/v1.2.0.
The primary release artifact of KubeVirt is the git tree. The release tag is
signed and can be verified using
git tag -v v1.2.0
.Pre-built containers are published on Quay and can be viewed at: https://quay.io/kubevirt/.
Notable changes
API change
Bug fix
Status.GuestOSInfo.Version
Deprecation
SIG-compute
vmRolloutStrategy
setting to define whether changes to VMs should either be always staged or live-updated when possible.kubevirt.io:default
clusterRole to get,list kubevirtsMachine
SIG-storage
SIG-network
SIG-infra
SIG-scale
Monitoring
Uncategorized
Contributors
65 people contributed to this release:
52 fossedihelm [email protected]
38 Luboslav Pivarc [email protected]
34 Alona Paz [email protected]
33 Edward Haas [email protected]
31 Brian Carey [email protected]
27 João Vilaça [email protected]
25 Or Mergi [email protected]
24 Dan Kenigsberg [email protected]
24 Jed Lejosne [email protected]
19 Victor Toso [email protected]
16 Alex Kalenyuk [email protected]
16 Antonio Cardace [email protected]
16 Ram Lavi [email protected]
14 Orel Misan [email protected]
13 Felix Matouschek [email protected]
11 Alvaro Romero [email protected]
11 Or Shoval [email protected]
10 Dharmit Shah [email protected]
8 Alice Frosi [email protected]
7 Fabian Deutsch [email protected]
7 howard zhang [email protected]
7 stirabos [email protected]
6 Vasiliy Ulyanov [email protected]
6 prnaraya [email protected]
5 Daniel Hiller [email protected]
4 Denis Ollier [email protected]
4 Igor Bezukh [email protected]
3 Alexander Wels [email protected]
3 Michael Henriksen [email protected]
3 Nahshon Unna-Tsameret [email protected]
2 Dalia Frank [email protected]
2 Jan Schintag [email protected]
2 Javier Cano Cano [email protected]
2 Shelly Kagan [email protected]
2 shenwei [email protected]
2 wuhanqing [email protected]
2 zhuanlan [email protected]
1 Alay Patel [email protected]
1 Andrea Bolognani [email protected]
1 Andrej Krejcir [email protected]
1 Andrew Burden [email protected]
1 Bart Vercoulen [email protected]
1 Ben Oukhanov [email protected]
1 Eng Zer Jun [email protected]
1 Enrique Llorente [email protected]
1 Erik Panter [email protected]
1 German Maglione [email protected]
1 Hidehisa Shitomi [email protected]
1 Karel Simon [email protected]
1 Lee Yarwood [email protected]
1 Marcelo Amaral <marcelo.amaral1@ibm.com>
1 Ohad [email protected]
1 Ondrej Pokorny [email protected]
1 Romain Decker [email protected]
1 Wenhui Zhang [email protected]
1 cfillekes [email protected]
1 haojue [email protected]
1 matthewei [email protected]
1 matthewei [email protected]
1 muxuelan [email protected]
1 rokkiter [email protected]
1 wangjihai [email protected]
1 xiaofang [email protected]
Additional Resources
-----BEGIN PGP SIGNATURE-----
iQJIBAABCAAyFiEEL3WFe2eU+K2zCASGa/gKvUPjd9MFAmXnf6AUHGFjYXJkYWNl
QHJlZGhhdC5jb20ACgkQa/gKvUPjd9MnKhAAq7FarHyi742Ara/2KdSnICUrwx2w
ud9VQvPuvb0t9PbH4feUZar5cGg1thFZXf7kx5xk+1vEvHD1Wue5h2t5i0+qq17C
om5fs4ZRy7zIiFWftAglcqLC/3iMTODo3esmReY5ALkwgDgXWRMORBVTAt34xI9+
PO2zTDB3caO1Dr5oDXVVLrgxMl2uPmhZkh46nlgq3AGtmByWrWO3Zdg0S9ym7RMK
pA0E+71MX32Tti25lMkdLs4I0+kKHMIdHoLjedYGDoJ8Z+rDqg1e/9JF6/4z/Zl5
ArxMo0HDXmDhLqE4zJN7UdQGUppjj+CiGe4Eiox0rj4nj34vjlHOQDvD2dYdOs4l
+Ca8vPzPMf7dCwuBra7VHJN1t62+wzoqxr1mNQ6Yhf2z87+MCm6i25h8V279ivSA
qervlzzBjBDj9H+IwzSZET9sY8uAASz3lvSolhN9JBzX2J5vZXapYpKsbrSMBhOX
nyaOUu75Ow7f67fJBnKkF+NR00gtMgPWTvu+rg1yvLFV0W3cTmFJK3aWkktNHwId
SQVdCwODyDH9ZlYwceugiqBcEVPUaRcwpFC6kfJBejBsifG4OVgSzHQ5YDNmU2bc
pzM6JMxpUnJw3o4VnsM0HdV2q0qb7jcASRVaHTs1lW/Xymiyrlq00sX8mf6Lz0fl
Rwne5ssktT+kHd0=
=WB1r
-----END PGP SIGNATURE-----
v1.1.1
Compare Source
tag v1.1.1
Tagger: Luboslav Pivarc [email protected]
This release follows v1.1.0 and consists of 110 changes, contributed by 17 people, leading to 258 files changed, 12215 insertions(+), 3245 deletions(-).
The source code and selected binaries are available for download at: https://github.com/kubevirt/kubevirt/releases/tag/v1.1.1.
The primary release artifact of KubeVirt is the git tree. The release tag is
signed and can be verified using
git tag -v v1.1.1
.Pre-built containers are published on Quay and can be viewed at: https://quay.io/kubevirt/.
Notable changes
Contributors
17 people contributed to this release:
18 Edward Haas [email protected]
15 Ram Lavi [email protected]
14 Alona Paz [email protected]
6 Or Mergi [email protected]
5 Antonio Cardace [email protected]
5 Vasiliy Ulyanov [email protected]
4 Alex Kalenyuk [email protected]
4 Denis Ollier [email protected]
3 fossedihelm [email protected]
2 Orel Misan [email protected]
2 Victor Toso [email protected]
1 Enrique Llorente [email protected]
1 Felix Matouschek [email protected]
1 Karel Simon [email protected]
1 Michael Henriksen [email protected]
Additional Resources
-----BEGIN PGP SIGNATURE-----
iIkEABEIADEWIQS5aL5huPTZew1hSy9m6XN7mspnmQUCZYlexhMcbHBpdmFyY0By
ZWRoYXQuY29tAAoJEGbpc3uaymeZt1oA/RZZ8Ci4pBvm0KFbzAug28NiCXeTN0qn
DPomhtehWMecAQCpKWSJBJz3r2E6eD8R8zECZPdQRRx3SrimSCQX2ZLoPA==
=uiB8
-----END PGP SIGNATURE-----
Merge pull request #10757 from RamLavi/release-1.1_add-full-pcpu-only-support
[release 1.1] isolateEmulatorThread: Add full-pcpu-only support
Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Renovate Bot.