containerd/contrib
Danny Canter 52ef3468bc Update Go to 1.20.6,1.19.11
go1.20.6 (released 2023-07-11) includes a security fix to the net/http
package, as well as bug fixes to the compiler, cgo, the cover tool, the
go command, the runtime, and the crypto/ecdsa, go/build, go/printer,
net/mail, and text/template packages. See the Go 1.20.6 milestone on
our issue tracker for details.

https://github.com/golang/go/issues?q=milestone%3AGo1.20.6+label%3ACherryPickApproved

Full diff: https://github.com/golang/go/compare/go1.20.5...go1.20.6

These minor releases include 1 security fixes following the security policy:

- net/http: insufficient sanitization of Host header

The HTTP/1 client did not fully validate the contents of the Host header.
A maliciously crafted Host header could inject additional headers or
entire requests. The HTTP/1 client now refuses to send requests containing
an invalid Request.Host or Request.URL.Host value.

Thanks to Bartek Nowotarski for reporting this issue.

Includes security fixes for CVE-2023-29406 and Go issue https://go.dev/issue/60374

Signed-off-by: Danny Canter <danny@dcantah.dev>
2023-07-11 14:34:23 -07:00
..
ansible upgrade registry.k8s.io/pause version 2023-05-28 07:59:10 +08:00
apparmor contrib/apparmor: remove code related to apparmor_parser version 2023-02-17 00:15:36 +01:00
autocomplete Fix zsh autocomplete script 2020-02-11 19:56:27 +08:00
aws Move snapshotters benchmark to a separate package 2019-04-02 14:42:21 -07:00
diffservice OCI: Add From/ToProto helpers for Descriptor 2023-06-28 12:16:20 -07:00
Dockerfile.test.d contrib/Dockerfile.test: add "integration", "cri-integration", "critest" stages 2023-01-03 20:19:38 +09:00
fuzz pkg/cri/sbserver: experimental NRI integration for CRI. 2023-02-13 22:08:18 +02:00
gce Update gce contrib to use v2 by default 2023-03-15 09:18:16 -07:00
nvidia replace uses of os/exec with golang.org/x/sys/execabs 2021-08-25 18:11:09 +02:00
seccomp seccomp: always allow name_to_handle_at 2023-06-28 05:50:24 -06:00
snapshotservice Snapshots: Add From/ToProto helpers for types 2023-06-28 12:17:52 -07:00
Dockerfile.test Update Go to 1.20.6,1.19.11 2023-07-11 14:34:23 -07:00
README.md Add readme to contib 2017-09-18 11:47:27 -04:00

contrib

The contrib directory contains packages that do not belong in the core containerd packages but still contribute to overall containerd usability.

Package such as Apparmor or Selinux are placed in contrib because they are platform dependent and often require higher level tools and profiles to work.

Packaging and other built tools can be added to contrib to aid in packaging containerd for various distributions.

Testing

Code in the contrib directory may or may not have been tested in the normal test pipeline for core components.