[release-1.11] NETOBSERV-2598: NETOBSERV-2517: Remove dependency on oc/kubectl#461
Conversation
The --filename argument of the go binary, which isn't used at the moment, is not sanitized for path traversal. This could be an unnoticed vulnerability if we chose to leverage it later on. This change uses go 1.24 "os.Root" API to prevent path traversal.
For some reason (??) it worked for get-flows but not for get-metrics ... "eval" makes it work for metrics too
|
@openshift-cherrypick-robot: Ignoring requests to cherry-pick non-bug issues: NETOBSERV-2598 DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. |
|
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: The full list of commands accepted by this bot can be found here. DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
|
Hi @openshift-cherrypick-robot. Thanks for your PR. I'm waiting for a netobserv member to verify that this patch is reasonable to test. If it is, they should reply with Once the patch is verified, the new status will be reflected by the I understand the commands that are listed here. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
Codecov Report❌ Patch coverage is
Additional details and impacted files@@ Coverage Diff @@
## release-1.11 #461 +/- ##
================================================
+ Coverage 12.95% 13.18% +0.22%
================================================
Files 19 20 +1
Lines 2439 2443 +4
================================================
+ Hits 316 322 +6
+ Misses 2099 2095 -4
- Partials 24 26 +2
Flags with carried forward coverage won't be shown. Click here to find out more.
🚀 New features to boost your workflow:
|
This is an automated cherry-pick of #457
/assign jotak