Merged
Conversation
….com/aws/aws-sdk-go-v2/config-1.28.5
Bumps [github.com/aws/aws-sdk-go-v2/service/route53](https://github.com/aws/aws-sdk-go-v2) from 1.45.2 to 1.46.2. - [Release notes](https://github.com/aws/aws-sdk-go-v2/releases) - [Commits](aws/aws-sdk-go-v2@service/rds/v1.45.2...service/ecs/v1.46.2) --- updated-dependencies: - dependency-name: github.com/aws/aws-sdk-go-v2/service/route53 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
….com/aws/aws-sdk-go-v2/service/route53-1.46.2
Bumps [github.com/aws/aws-sdk-go-v2/service/ssm](https://github.com/aws/aws-sdk-go-v2) from 1.55.3 to 1.55.6. - [Release notes](https://github.com/aws/aws-sdk-go-v2/releases) - [Commits](aws/aws-sdk-go-v2@service/iot/v1.55.3...service/iot/v1.55.6) --- updated-dependencies: - dependency-name: github.com/aws/aws-sdk-go-v2/service/ssm dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
….com/aws/aws-sdk-go-v2/service/ssm-1.55.6
Bumps [github.com/aws/aws-sdk-go-v2/service/ec2](https://github.com/aws/aws-sdk-go-v2) from 1.189.0 to 1.193.0. - [Release notes](https://github.com/aws/aws-sdk-go-v2/releases) - [Commits](aws/aws-sdk-go-v2@service/ec2/v1.189.0...service/ec2/v1.193.0) --- updated-dependencies: - dependency-name: github.com/aws/aws-sdk-go-v2/service/ec2 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [golang.org/x/crypto](https://github.com/golang/crypto) from 0.28.0 to 0.29.0. - [Commits](golang/crypto@v0.28.0...v0.29.0) --- updated-dependencies: - dependency-name: golang.org/x/crypto dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [github.com/onsi/ginkgo/v2](https://github.com/onsi/ginkgo) from 2.21.0 to 2.22.0. - [Release notes](https://github.com/onsi/ginkgo/releases) - [Changelog](https://github.com/onsi/ginkgo/blob/master/CHANGELOG.md) - [Commits](onsi/ginkgo@v2.21.0...v2.22.0) --- updated-dependencies: - dependency-name: github.com/onsi/ginkgo/v2 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
….org/x/crypto-0.29.0
….com/onsi/ginkgo/v2-2.22.0
Bumps [github.com/aws/aws-sdk-go-v2/service/ssm](https://github.com/aws/aws-sdk-go-v2) from 1.55.6 to 1.56.0. - [Release notes](https://github.com/aws/aws-sdk-go-v2/releases) - [Commits](aws/aws-sdk-go-v2@service/iot/v1.55.6...service/s3/v1.56.0) --- updated-dependencies: - dependency-name: github.com/aws/aws-sdk-go-v2/service/ssm dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
….com/aws/aws-sdk-go-v2/service/ssm-1.56.0
….com/aws/aws-sdk-go-v2/service/ec2-1.193.0
Bumps the k8sio group with 1 update: [k8s.io/apimachinery](https://github.com/kubernetes/apimachinery). Updates `k8s.io/apimachinery` from 0.31.2 to 0.31.3 - [Commits](kubernetes/apimachinery@v0.31.2...v0.31.3) --- updated-dependencies: - dependency-name: k8s.io/apimachinery dependency-type: direct:production update-type: version-update:semver-patch dependency-group: k8sio ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [github.com/aws/aws-sdk-go-v2](https://github.com/aws/aws-sdk-go-v2) from 1.32.5 to 1.32.6. - [Release notes](https://github.com/aws/aws-sdk-go-v2/releases) - [Commits](aws/aws-sdk-go-v2@v1.32.5...v1.32.6) --- updated-dependencies: - dependency-name: github.com/aws/aws-sdk-go-v2 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [github.com/aws/aws-sdk-go-v2/service/ssm](https://github.com/aws/aws-sdk-go-v2) from 1.56.0 to 1.56.1. - [Release notes](https://github.com/aws/aws-sdk-go-v2/releases) - [Commits](aws/aws-sdk-go-v2@service/s3/v1.56.0...service/s3/v1.56.1) --- updated-dependencies: - dependency-name: github.com/aws/aws-sdk-go-v2/service/ssm dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
…e5d201adef Bump k8s.io/apimachinery from 0.31.2 to 0.31.3 in the k8sio group
Bumps [sigs.k8s.io/controller-runtime](https://github.com/kubernetes-sigs/controller-runtime) from 0.19.1 to 0.19.3. - [Release notes](https://github.com/kubernetes-sigs/controller-runtime/releases) - [Changelog](https://github.com/kubernetes-sigs/controller-runtime/blob/main/RELEASE.md) - [Commits](kubernetes-sigs/controller-runtime@v0.19.1...v0.19.3) --- updated-dependencies: - dependency-name: sigs.k8s.io/controller-runtime dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
…8s.io/controller-runtime-0.19.3 Bump sigs.k8s.io/controller-runtime from 0.19.1 to 0.19.3
Bumps [golang.org/x/crypto](https://github.com/golang/crypto) from 0.29.0 to 0.31.0. - [Commits](golang/crypto@v0.29.0...v0.31.0) --- updated-dependencies: - dependency-name: golang.org/x/crypto dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
…x/crypto-0.31.0 Bump golang.org/x/crypto from 0.29.0 to 0.31.0
….com/aws/aws-sdk-go-v2-1.32.6 Bump github.com/aws/aws-sdk-go-v2 from 1.32.5 to 1.32.6
….com/aws/aws-sdk-go-v2/service/ssm-1.56.1 Bump github.com/aws/aws-sdk-go-v2/service/ssm from 1.56.0 to 1.56.1
Signed-off-by: Tariq Ibrahim <tibrahim@nvidia.com>
Signed-off-by: shiva kumar <shivaku@nvidia.com>
Add GitHub metadata as AWS Tags
Bumps [github.com/aws/aws-sdk-go-v2/service/ec2](https://github.com/aws/aws-sdk-go-v2) from 1.193.0 to 1.198.1. - [Release notes](https://github.com/aws/aws-sdk-go-v2/releases) - [Commits](aws/aws-sdk-go-v2@service/ec2/v1.193.0...service/ec2/v1.198.1) --- updated-dependencies: - dependency-name: github.com/aws/aws-sdk-go-v2/service/ec2 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
….com/aws/aws-sdk-go-v2/service/ec2-1.198.1 Bump github.com/aws/aws-sdk-go-v2/service/ec2 from 1.193.0 to 1.198.1
Bumps [github.com/onsi/gomega](https://github.com/onsi/gomega) from 1.35.1 to 1.36.2. - [Release notes](https://github.com/onsi/gomega/releases) - [Changelog](https://github.com/onsi/gomega/blob/master/CHANGELOG.md) - [Commits](onsi/gomega@v1.35.1...v1.36.2) --- updated-dependencies: - dependency-name: github.com/onsi/gomega dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
Add unit tests across the project
Bumps [github.com/aws/aws-sdk-go-v2/service/ec2](https://github.com/aws/aws-sdk-go-v2) from 1.218.0 to 1.221.0. - [Release notes](https://github.com/aws/aws-sdk-go-v2/releases) - [Changelog](https://github.com/aws/aws-sdk-go-v2/blob/main/changelog-template.json) - [Commits](aws/aws-sdk-go-v2@service/ec2/v1.218.0...service/ec2/v1.221.0) --- updated-dependencies: - dependency-name: github.com/aws/aws-sdk-go-v2/service/ec2 dependency-version: 1.221.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
….com/aws/aws-sdk-go-v2/service/ec2-1.221.0 Bump github.com/aws/aws-sdk-go-v2/service/ec2 from 1.218.0 to 1.221.0
Bumps the k8sio group with 1 update in the / directory: [k8s.io/apimachinery](https://github.com/kubernetes/apimachinery). Updates `k8s.io/apimachinery` from 0.33.0 to 0.33.1 - [Commits](kubernetes/apimachinery@v0.33.0...v0.33.1) --- updated-dependencies: - dependency-name: k8s.io/apimachinery dependency-version: 0.33.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: k8sio ... Signed-off-by: dependabot[bot] <support@github.com>
…5c65782ea8 Bump k8s.io/apimachinery from 0.33.0 to 0.33.1 in the k8sio group across 1 directory
Bumps [sigs.k8s.io/controller-runtime](https://github.com/kubernetes-sigs/controller-runtime) from 0.20.4 to 0.21.0. - [Release notes](https://github.com/kubernetes-sigs/controller-runtime/releases) - [Changelog](https://github.com/kubernetes-sigs/controller-runtime/blob/main/RELEASE.md) - [Commits](kubernetes-sigs/controller-runtime@v0.20.4...v0.21.0) --- updated-dependencies: - dependency-name: sigs.k8s.io/controller-runtime dependency-version: 0.21.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
…8s.io/controller-runtime-0.21.0 Bump sigs.k8s.io/controller-runtime from 0.20.4 to 0.21.0
Signed-off-by: Carlos Eduardo Arango Gutierrez <eduardoa@nvidia.com>
Enhance CLI by adding instance management
Signed-off-by: Carlos Eduardo Arango Gutierrez <eduardoa@nvidia.com>
Signed-off-by: Carlos Eduardo Arango Gutierrez <eduardoa@nvidia.com>
Signed-off-by: Carlos Eduardo Arango Gutierrez <eduardoa@nvidia.com>
Enable containerd 2.0+ installation
Signed-off-by: Carlos Eduardo Arango Gutierrez <eduardoa@nvidia.com>
Signed-off-by: Carlos Eduardo Arango Gutierrez <eduardoa@nvidia.com>
Signed-off-by: Carlos Eduardo Arango Gutierrez <eduardoa@nvidia.com>
Signed-off-by: Carlos Eduardo Arango Gutierrez <eduardoa@nvidia.com>
Signed-off-by: Carlos Eduardo Arango Gutierrez <eduardoa@nvidia.com>
Signed-off-by: Carlos Eduardo Arango Gutierrez <eduardoa@nvidia.com>
Bug fixes after v0.2.8 release
Signed-off-by: Carlos Eduardo Arango Gutierrez <eduardoa@nvidia.com>
Add a safely exit to securly close the ssh connection
Bumps [github.com/aws/aws-sdk-go-v2/service/ec2](https://github.com/aws/aws-sdk-go-v2) from 1.221.0 to 1.222.0. - [Release notes](https://github.com/aws/aws-sdk-go-v2/releases) - [Changelog](https://github.com/aws/aws-sdk-go-v2/blob/main/changelog-template.json) - [Commits](aws/aws-sdk-go-v2@service/ec2/v1.221.0...service/ec2/v1.222.0) --- updated-dependencies: - dependency-name: github.com/aws/aws-sdk-go-v2/service/ec2 dependency-version: 1.222.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
….com/aws/aws-sdk-go-v2/service/ec2-1.222.0 Bump github.com/aws/aws-sdk-go-v2/service/ec2 from 1.221.0 to 1.222.0
| ssh.PublicKeys(signer), | ||
| }, | ||
| HostKeyCallback: ssh.InsecureIgnoreHostKey(), | ||
| HostKeyCallback: ssh.InsecureIgnoreHostKey(), // nolint:gosec |
Check failure
Code scanning / CodeQL
Use of insecure HostKeyCallback implementation
Show autofix suggestion
Hide autofix suggestion
Copilot Autofix
AI 10 months ago
To fix the issue, replace the insecure ssh.InsecureIgnoreHostKey() with a secure host key callback implementation. The ssh.FixedHostKey function can be used if the host's public key is known in advance. This requires loading the public key from a file or another trusted source and using it to validate the server's host key during the SSH handshake.
Steps to implement the fix:
- Load the server's public key from a trusted file (e.g.,
allowed_hostkey.pub). - Parse the public key using
ssh.ParsePublicKey. - Replace
ssh.InsecureIgnoreHostKey()withssh.FixedHostKey(publicKey)in theHostKeyCallbackfield of thessh.ClientConfig.
Suggested changeset
1
cmd/cli/dryrun/dryrun.go
| @@ -145,3 +145,16 @@ | ||
| }, | ||
| HostKeyCallback: ssh.InsecureIgnoreHostKey(), // nolint:gosec | ||
| HostKeyCallback: func(hostname string, remote net.Addr, key ssh.PublicKey) error { | ||
| publicKeyBytes, err := os.ReadFile("allowed_hostkey.pub") | ||
| if err != nil { | ||
| return fmt.Errorf("failed to read allowed host key file: %v", err) | ||
| } | ||
| publicKey, err := ssh.ParsePublicKey(publicKeyBytes) | ||
| if err != nil { | ||
| return fmt.Errorf("failed to parse allowed host key: %v", err) | ||
| } | ||
| if ssh.KeysEqual(publicKey, key) { | ||
| return nil | ||
| } | ||
| return fmt.Errorf("host key verification failed for host %s", hostname) | ||
| }, | ||
| } |
Copilot is powered by AI and may make mistakes. Always verify output.
Unable to commit as this autofix suggestion is now outdated
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
No description provided.