Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Release the operator v0.87.0 #2207

Closed
Tracked by #8644
dmitryax opened this issue Oct 11, 2023 · 9 comments · Fixed by #2242
Closed
Tracked by #8644

Release the operator v0.87.0 #2207

dmitryax opened this issue Oct 11, 2023 · 9 comments · Fixed by #2242

Comments

@dmitryax
Copy link
Member

No description provided.

@dmitryax dmitryax transferred this issue from open-telemetry/opentelemetry-collector Oct 11, 2023
@pavolloffay
Copy link
Member

@TylerHelmuth
Copy link
Member

@pavolloffay do you want to go right into this one or wait a week since we just released 0.86.0?

@pavolloffay
Copy link
Member

I don't have any preference. It depends if other folks want to get in some functionality cc) @open-telemetry/operator-approvers @open-telemetry/operator-maintainers

@pavolloffay
Copy link
Member

I would like to get this one in #2215

@pavolloffay
Copy link
Member

It would be great to wait for 0.87.1 collector that fixes CVE-2023-44487

@mx-psi
Copy link
Member

mx-psi commented Oct 13, 2023

We have some guidance here around patch releases: https://github.com/open-telemetry/opentelemetry-collector/blob/main/docs/release.md#bugfix-release-criteria

We aim to provide a release that fixes security-related issues in at most 30 days since they are publicly announced; with the current release schedule this means security issues will typically not warrant a bugfix release. An exception is critical vulnerabilities (CVSSv3 score >= 9.0), which will warrant a release within five business days.

Do we consider this to be a critical vulnerability? The score seems to be 5.3 (moderate) on Github's tracker, but I am not sure if this is what we should be looking at (the CVE talks about Swift specifically).

@pavolloffay
Copy link
Member

Thanks for the info. This is probably a better tracker GHSA-4374-p667-p6c8

@mx-psi
Copy link
Member

mx-psi commented Oct 13, 2023

Some more trackers:

The CVSS v3 Base Score is 7.5 and is classified as 'Important' (in between Moderate and Critical) or of 'Medium' priority.

@TylerHelmuth
Copy link
Member

I am prepping the release PR, but I believe we need to merge #2239 before the next release.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

4 participants