OCPBUGS-68220: Update logrus to 1.9.3 to address CVE-2025-65637#316
OCPBUGS-68220: Update logrus to 1.9.3 to address CVE-2025-65637#316davegord wants to merge 1 commit intoopenshift:release-4.17from
Conversation
This updates the github.com/sirupsen/logrus dependency from v1.9.0 to v1.9.3 to fix CVE-2025-65637, a security vulnerability in the logrus logging library. 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the You can disable this status message by setting the Use the checkbox below for a quick retry:
✨ Finishing Touches🧪 Generate unit tests (beta)
Tip Issue Planner is now in beta. Read the docs and try it out! Share your feedback on Discord. Comment |
|
@davegord: This pull request references Jira Issue OCPBUGS-68220, which is invalid:
Comment The bug has been updated to refer to the pull request using the external bug tracker. DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. |
|
/jira refresh |
|
@davegord: This pull request references Jira Issue OCPBUGS-68220, which is valid. The bug has been moved to the POST state. 7 validation(s) were run on this bug
DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. |
|
@davegord: This pull request references Jira Issue OCPBUGS-68220, which is valid. 7 validation(s) were run on this bug
DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. |
|
/retest-required |
|
@davegord: all tests passed! Full PR test history. Your PR dashboard. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here. |
|
/lgtm |
|
@dusk125: This PR has been marked as verified by DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. |
|
@dusk125: The label(s) DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
|
/label backport-risk-assessed |
|
[APPROVALNOTIFIER] This PR is APPROVED Approval requirements bypassed by manually added approval. This pull-request has been approved by: davegord, dusk125 The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
|
@coderabbitai skip |
|
✅ Actions performedReviews paused. |
|
@coderabbitai help |
ChatThere are 3 ways to chat with CodeRabbit:
CodeRabbit commands
Other keywords and placeholders
Status, support, documentation and community
|
|
@coderabbitai ignore |
✅ Actions performedReviews paused. |
|
@benluddy can you override the coderabbit review? |
|
@coderabbitai resume |
✅ Actions performedReviews resumed. |
|
@coderabbitai resolve |
✅ Actions performedComments resolved. Auto-approval is disabled; enable |
Summary
Changes
Test plan
🤖 Generated with Claude Code
Note
Low Risk
Low risk dependency update focused on a vendored logging library; main impact is in
logrusWriterLevelscanning behavior, which could slightly change log line splitting/formatting for very large writes.Overview
Updates vendored
github.com/sirupsen/logrusfromv1.9.0tov1.9.3(includinggo.mod/go.sum/vendor/modules.txt) to pick up the CVE fix.The updated
logruswriter.gochanges howEntry.WriterLevelreads from the pipe: it configures the scanner to safely handle large inputs (chunking up tobufio.MaxScanTokenSize) and trims trailing\r\nbefore logging, plus minor README/vendor doc adjustments.Written by Cursor Bugbot for commit c573cef. This will update automatically on new commits. Configure here.