Skip to content

Bump golang.org/x/crypto v0.45.0 to address CVEs on crypto v0.36.0 #20963

@dtma007

Description

@dtma007

What would you like to be added?

These 2 CVEs are reported on versions of golang.org/x/crypto before 0.45.0

Could we get a released version of etcd with golang.org/x/crypto 0.45.0 ? (I noticed main branch already has it:https://github.com/etcd-io/etcd/blob/main/go.mod#L99 , but the released versions will have crypto 0.36.0)

Thanks.

Why is this needed?

To address security vulnerabilities:

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions