Skip to content

Fix CVE in release-0.24#2157

Open
dfarrell07 wants to merge 2 commits intosubmariner-io:release-0.24from
dfarrell07:fix-0.24-cves-2026-05-06
Open

Fix CVE in release-0.24#2157
dfarrell07 wants to merge 2 commits intosubmariner-io:release-0.24from
dfarrell07:fix-0.24-cves-2026-05-06

Conversation

@dfarrell07
Copy link
Copy Markdown
Member

See commit message for details.

@submariner-bot
Copy link
Copy Markdown
Contributor

🤖 Created branch: z_pr2157/dfarrell07/fix-0.24-cves-2026-05-06
🚀 Full E2E won't run until the "ready-to-test" label is applied. I will add it automatically once the PR has 2 approvals, or you can add it manually.

@coderabbitai
Copy link
Copy Markdown

coderabbitai Bot commented May 6, 2026

Warning

Rate limit exceeded

@dfarrell07 has exceeded the limit for the number of commits that can be reviewed per hour. Please wait 55 minutes and 13 seconds before requesting another review.

To continue reviewing without waiting, purchase usage credits in the billing tab.

⌛ How to resolve this issue?

After the wait time has elapsed, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

We recommend that you space out your commits to avoid hitting the rate limit.

🚦 How do rate limits work?

CodeRabbit enforces hourly rate limits for each developer per organization.

Our paid plans have higher rate limits than the trial, open-source and free plans. In all cases, we re-allow further reviews after a brief timeout.

Please see our FAQ for further information.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: f174a9d9-1af4-475b-8ff8-dd0bb68e009b

📥 Commits

Reviewing files that changed from the base of the PR and between f7591d8 and f8f4bf6.

⛔ Files ignored due to path filters (1)
  • coredns/go.sum is excluded by !**/*.sum
📒 Files selected for processing (2)
  • .lichen.yaml
  • coredns/go.mod

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

Full package: github.com/coredns/coredns
Fixes: GHSA-2wpx-qpw2-g5h5, GHSA-63cw-r7xf-jmwr,
       GHSA-h8mm-c463-wjq3, GHSA-qhmp-q7xh-99rh,
       GHSA-vp29-5652-4fw9

Signed-off-by: Daniel Farrell <dfarrell@redhat.com>
@dfarrell07 dfarrell07 force-pushed the fix-0.24-cves-2026-05-06 branch from 7a4113c to 69cc9a1 Compare May 6, 2026 20:30
@dfarrell07 dfarrell07 moved this to In Review in Submariner 0.24 May 6, 2026
@dfarrell07 dfarrell07 force-pushed the fix-0.24-cves-2026-05-06 branch from 4a1d082 to 68df046 Compare May 6, 2026 21:53
Indirect dep pulled in by coredns v1.14.3 upgrade. MPL-2.0
approved by CNCF GB exception (2019-03-11) for golang-lru v1;
v2 is the same project/repo/license.

Signed-off-by: Daniel Farrell <dfarrell@redhat.com>
@dfarrell07 dfarrell07 force-pushed the fix-0.24-cves-2026-05-06 branch from 68df046 to f8f4bf6 Compare May 6, 2026 21:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: In Review

Development

Successfully merging this pull request may close these issues.

2 participants