Skip to content

[Backport into 5.18] Backporting CVE fixes#1569

Merged
liranmauda merged 9 commits intonoobaa:5.18from
liranmauda:liran-backport-into-5.18
Mar 24, 2025
Merged

[Backport into 5.18] Backporting CVE fixes#1569
liranmauda merged 9 commits intonoobaa:5.18from
liranmauda:liran-backport-into-5.18

Conversation

@liranmauda
Copy link
Contributor

Explain the changes

  1. Backporting CVE fixes

ismaelpuerto and others added 9 commits March 24, 2025 10:48
Signed-off-by: Ismael Puerto Freire <ipuertofreire@gmail.com>

Expand bucket replication documentation

Signed-off-by: Ben <belimele@redhat.com>

Add S3 compatibility documentation

Signed-off-by: Ben <belimele@redhat.com>

Noobaa/Operator: Display error message

While deleting OBC or Bucketclass which does not exist,
we should display an error message and should not silently
give success.

Signed-off-by: Ashish Pandey <aspandey@redhat.com>

Add bucket types documentation

Signed-off-by: Ben <belimele@redhat.com>

Update `readme.md`

Signed-off-by: Ben <belimele@redhat.com>

noobaa/operator: Add tests for deletion

Adding tests for deletion of non exiisting OBC and Bucketclass

Signed-off-by: Ashish Pandey <aspandey@redhat.com>

bucket notification - check pvcName, not pvc DFBUGS 988, 991 (noobaa#1485)

Signed-off-by: Amit Prinz Setter <alphaprinz@gmail.com>

Fix for region fetch from GetAWSRegion()

Signed-off-by: Aayush Chouhan <achouhan@redhat.com>

Bucket Notification - connect filename simplification (noobaa#1494)

Signed-off-by: Amit Prinz Setter <alphaprinz@gmail.com>
(cherry picked from commit 6ceb4f8)
Signed-off-by: liranmauda <liran.mauda@gmail.com>
(cherry picked from commit a4c0a30)
Bumps [github.com/golang-jwt/jwt/v4](https://github.com/golang-jwt/jwt) from 4.5.0 to 4.5.1.
- [Release notes](https://github.com/golang-jwt/jwt/releases)
- [Changelog](https://github.com/golang-jwt/jwt/blob/main/VERSION_HISTORY.md)
- [Commits](golang-jwt/jwt@v4.5.0...v4.5.1)

---
updated-dependencies:
- dependency-name: github.com/golang-jwt/jwt/v4
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
(cherry picked from commit ba8e415)
- Bump rook

Signed-off-by: liranmauda <liran.mauda@gmail.com>
(cherry picked from commit 3c40f1f)
Bumps [github.com/go-jose/go-jose/v4](https://github.com/go-jose/go-jose) from 4.0.4 to 4.0.5.
- [Release notes](https://github.com/go-jose/go-jose/releases)
- [Changelog](https://github.com/go-jose/go-jose/blob/main/CHANGELOG.md)
- [Commits](go-jose/go-jose@v4.0.4...v4.0.5)

---
updated-dependencies:
- dependency-name: github.com/go-jose/go-jose/v4
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
(cherry picked from commit b441aa4)
Bumps [golang.org/x/net](https://github.com/golang/net) from 0.34.0 to 0.36.0.
- [Commits](golang/net@v0.34.0...v0.36.0)

---
updated-dependencies:
- dependency-name: golang.org/x/net
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
(cherry picked from commit 8961293)
update `golang.org/x/oauth2` to avoid CVE

Signed-off-by: liranmauda <liran.mauda@gmail.com>
(cherry picked from commit 29a57ee)
Bumps [github.com/golang-jwt/jwt/v4](https://github.com/golang-jwt/jwt) from 4.5.1 to 4.5.2.
- [Release notes](https://github.com/golang-jwt/jwt/releases)
- [Changelog](https://github.com/golang-jwt/jwt/blob/main/VERSION_HISTORY.md)
- [Commits](golang-jwt/jwt@v4.5.1...v4.5.2)

---
updated-dependencies:
- dependency-name: github.com/golang-jwt/jwt/v4
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
(cherry picked from commit ea4eb08)
Bumps [github.com/golang-jwt/jwt/v5](https://github.com/golang-jwt/jwt) from 5.2.1 to 5.2.2.
- [Release notes](https://github.com/golang-jwt/jwt/releases)
- [Changelog](https://github.com/golang-jwt/jwt/blob/main/VERSION_HISTORY.md)
- [Commits](golang-jwt/jwt@v5.2.1...v5.2.2)

---
updated-dependencies:
- dependency-name: github.com/golang-jwt/jwt/v5
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
(cherry picked from commit 1769f72)
@liranmauda liranmauda merged commit 1a17057 into noobaa:5.18 Mar 24, 2025
14 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants