tarantool / tarantool/tt

build(deps): bump github.com/containerd/containerd from v1.6.38 to v1.7.29

Open
#1,214 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Go
Stars
113
Forks
18
Avg merge
4d 11h
Merged PRs (30d)
23

Description

Version 1.6.38 contains CVE-2024-25621 vulnerability. Based on recomendation, I'll bump to the minimal patched version.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Locate the Go dependency manifest that pins github.com/containerd/containerd and confirm the current v1.6.38 entry. Update it to v1.7.29, then run the repository's Go checks and verify the dependency resolves without the cited CVE.

Written by the indexing model from the issue text.

Assessment

Tech stack
go
Domain
build-system, cli, security
Issue type
Bug
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.