Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(dev): fix CVE-2024-47614 by bumping async-graphql #22371

Open
wants to merge 3 commits into
base: master
Choose a base branch
from

Conversation

pront
Copy link
Member

@pront pront commented Feb 5, 2025

Summary

https://github.com/vectordotdev/vector/security/dependabot/106

Change Type

  • Bug fix
  • New feature
  • Non-functional (chore, refactoring, docs)
  • Performance

Is this a breaking change?

  • Yes
  • No

How did you test this PR?

Does this PR include user facing changes?

  • Yes. Please add a changelog fragment based on our guidelines.
  • No. A maintainer will apply the "no-changelog" label to this PR.

Checklist

  • Please read our Vector contributor resources.
    • make check-all is a good command to run locally. This check is
      defined here. Some of these
      checks might not be relevant to your PR. For Rust changes, at the very least you should run:
      • cargo fmt --all
      • cargo clippy --workspace --all-targets -- -D warnings
      • cargo nextest run --workspace (alternatively, you can run cargo test --all)
  • If this PR introduces changes Vector dependencies (modifies Cargo.lock), please
    run dd-rust-license-tool write to regenerate the license inventory and commit the changes (if any). More details here.

References

@pront pront added the no-changelog Changes in this PR do not need user-facing explanations in the release changelog label Feb 5, 2025
@pront pront requested a review from a team as a code owner February 5, 2025 21:54
@pront pront requested review from jszwedko and removed request for a team February 5, 2025 21:55
@pront pront enabled auto-merge February 5, 2025 21:56
@datadog-vectordotdev
Copy link

datadog-vectordotdev bot commented Feb 5, 2025

Datadog Report

Branch report: pront/fix-CVE-2024-47614
Commit report: 239404f
Test service: vector

✅ 0 Failed, 7 Passed, 0 Skipped, 25.5s Total Time

@pront pront added this pull request to the merge queue Feb 5, 2025
@pront pront removed this pull request from the merge queue due to a manual request Feb 5, 2025
@pront pront enabled auto-merge February 6, 2025 21:26
@pront pront added this pull request to the merge queue Feb 6, 2025
@github-merge-queue github-merge-queue bot removed this pull request from the merge queue due to failed status checks Feb 7, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
no-changelog Changes in this PR do not need user-facing explanations in the release changelog
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants