NO-JIRA: Update sirupsen/logrus from v1.9.0 to v1.9.3 to fix CVE-2025-65637 [release-4.15]#2129
NO-JIRA: Update sirupsen/logrus from v1.9.0 to v1.9.3 to fix CVE-2025-65637 [release-4.15]#2129rissh wants to merge 1 commit intoopenshift:release-4.15from
Conversation
|
@rissh: This pull request explicitly references no jira issue. DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. |
|
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: rissh The full list of commands accepted by this bot can be found here. DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
|
@rissh: all tests passed! Full PR test history. Your PR dashboard. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here. |
|
Hey @p0lyn0mial @bertinatto , |
Bumps github.com/sirupsen/logrus from v1.9.0 to v1.9.3 to address GHSA-4f99-4q7p-p3gh.
Fixes CVE-2025-65637 (DoS in logrus Entry.Writer() for payloads >64KB).
Downstreams will pick this up once merged.
Related PRs :