Giter VIP home page Giter VIP logo

Comments (13)

ivanvc avatar ivanvc commented on July 17, 2024 2

We may want to hold the release after 7/2, as according to SIG-release's email

There is a Go update being released on 07/02

I do see some outstanding changes in the Go Release Dashboard. But I don't know how to check when the version will be released, and I'm not sure if it will come with another vulnerability fix.

from etcd.

ivanvc avatar ivanvc commented on July 17, 2024 1

After a sweep of fixes merged in the main branch after 3.5.14, I found these two potential backports:

Do we want to backport any of these?

I would appreciate another pair of eyes to do another pass.

I also volunteer to be a shadow for this release :)

from etcd.

jmhbnz avatar jmhbnz commented on July 17, 2024 1

@spzala or @wenjiaswe did either of you want to lead this release? If not I am happy to volunteer as release lead.

Do we want to backport any of these?

Will do some review soon, we also need to take a close look at recent bug reports and see if anything needs to be included: https://github.com/etcd-io/etcd/issues?q=is%3Aissue+label%3Atype%2Fbug+created%3A%3E%3D2024-04-30

from etcd.

wenjiaswe avatar wenjiaswe commented on July 17, 2024 1

@jmhbnz Yes, I am happy to do the release. It's a short week in US, maybe I can do it next week?

from etcd.

jmhbnz avatar jmhbnz commented on July 17, 2024 1

@jmhbnz Yes, I am happy to do the release. It's a short week in US, maybe I can do it next week?

SGTM - So release team will be:

Github handle Role
@jmhbnz Release advisor
@wenjiaswe Release lead
@ivanvc Release shadow

/assign @wenjiaswe, @ivanvc, @jmhbnz

from etcd.

wenjiaswe avatar wenjiaswe commented on July 17, 2024 1

@ivanvc @jmhbnz I will discuss with you two on chat. If anyone else interested in shadowing, please ping me in slack: wenjiaswe

from etcd.

ivanvc avatar ivanvc commented on July 17, 2024

Would you guys be available Monday, July 8th, at 11 a.m. PT? I'll be out next week starting Tuesday, so I won't be available if you want to schedule it for later that day, which is fine by me, we could see if someone else wants to shadow :)

from etcd.

ivanvc avatar ivanvc commented on July 17, 2024

@jmhbnz, after updating Go to address vulnerabilities (#18269), I think we now can release 3.4.34, right?

from etcd.

jmhbnz avatar jmhbnz commented on July 17, 2024

@jmhbnz, after updating Go to address vulnerabilities (#18269), I think we now can release 3.4.34, right?

What is the CVE score? NIST don't list it yet https://nvd.nist.gov/vuln/detail/CVE-2024-24791. Our patch release criteria is 7.5 https://github.com/etcd-io/etcd/blob/main/Documentation/contributor-guide/release.md#patch-release-criteria but I'm not opposed to start organising 3.4.34 anyway once this release is done.

from etcd.

ivanvc avatar ivanvc commented on July 17, 2024

What is the CVE score? NIST don't list it yet https://nvd.nist.gov/vuln/detail/CVE-2024-24791. Our patch release criteria is 7.5

That's a good point. I think there's no rush, and ultimately, there are no other outstanding changes for 3.4 other than the Go update.

from etcd.

ivanvc avatar ivanvc commented on July 17, 2024

Will do some review soon, we also need to take a close look at recent bug reports and see if anything needs to be included: https://github.com/etcd-io/etcd/issues?q=is%3Aissue+label%3Atype%2Fbug+created%3A%3E%3D2024-04-30

I reviewed these and couldn't find anything that caught my eye.
Do we want to backport any of #18247 (comment)?

from etcd.

jmhbnz avatar jmhbnz commented on July 17, 2024

I reviewed these and couldn't find anything that caught my eye. Do we want to backport any of #18247 (comment)?

Have raised backport proposals for both:

from etcd.

bearpaws avatar bearpaws commented on July 17, 2024

Are we still expecting the 3.5.15 release this week? Thanks.

from etcd.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.