Skip to content

[1.33] vendor: bump spdystream to v0.5.1#9888

Merged
haircommander merged 1 commit into
cri-o:release-1.33from
haircommander:spdy-1.33
Apr 15, 2026
Merged

[1.33] vendor: bump spdystream to v0.5.1#9888
haircommander merged 1 commit into
cri-o:release-1.33from
haircommander:spdy-1.33

Conversation

@haircommander

@haircommander haircommander commented Apr 14, 2026

Copy link
Copy Markdown
Member

fixes https://www.cve.org/CVERecord?id=CVE-2026-35469

What type of PR is this?

/kind dependency-change

What this PR does / why we need it:

Bumps spdystream to v0.5.1 to fix CVE-2026-35469

Which issue(s) this PR fixes:

None

Special notes for your reviewer:

Cherry-pick of #9884 to release-1.33
assisted by claude

Does this PR introduce a user-facing change?

Fix CVE-2026-35469 by updating spdystream dependency

fixes https://www.cve.org/CVERecord?id=CVE-2026-35469

Signed-off-by: Peter Hunt <pehunt@redhat.com>
@haircommander haircommander requested a review from mrunalp as a code owner April 14, 2026 18:41
@openshift-ci openshift-ci Bot added release-note Denotes a PR that will be considered when it comes time to generate release notes. dco-signoff: yes Indicates the PR's author has DCO signed all their commits. kind/dependency-change Categorizes issue or PR as related to changing dependencies labels Apr 14, 2026
@coderabbitai

coderabbitai Bot commented Apr 14, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 25672f3a-68cd-4c28-895f-a940cd78e2b0

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@openshift-ci openshift-ci Bot requested review from hasan4791 and klihub April 14, 2026 18:41
@openshift-ci

openshift-ci Bot commented Apr 14, 2026

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: haircommander

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-ci openshift-ci Bot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Apr 14, 2026
@haircommander haircommander added the lgtm Indicates that a PR is ready to be merged. label Apr 14, 2026
@openshift-ci

openshift-ci Bot commented Apr 14, 2026

Copy link
Copy Markdown
Contributor

@haircommander: The following test failed, say /retest to rerun all failed tests or /retest-required to rerun all mandatory failed tests:

Test name Commit Details Required Rerun command
ci/prow/e2e-gcp-ovn c7b2d29 link true /test e2e-gcp-ovn

Full PR test history. Your PR dashboard.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

@codecov

codecov Bot commented Apr 14, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 49.67%. Comparing base (bbba73d) to head (c7b2d29).
⚠️ Report is 2 commits behind head on release-1.33.

Additional details and impacted files
@@              Coverage Diff              @@
##           release-1.33    #9888   +/-   ##
=============================================
  Coverage         49.67%   49.67%           
=============================================
  Files               164      164           
  Lines             18353    18353           
=============================================
  Hits               9117     9117           
  Misses             8099     8099           
  Partials           1137     1137           
🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@haircommander haircommander merged commit 4197d28 into cri-o:release-1.33 Apr 15, 2026
42 of 56 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. dco-signoff: yes Indicates the PR's author has DCO signed all their commits. kind/dependency-change Categorizes issue or PR as related to changing dependencies lgtm Indicates that a PR is ready to be merged. release-note Denotes a PR that will be considered when it comes time to generate release notes.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant