Sync with hyperledger-labs/fabric-operator#109
Open
github-actions[bot] wants to merge 60 commits intobestchains:mainfrom
Open
Sync with hyperledger-labs/fabric-operator#109github-actions[bot] wants to merge 60 commits intobestchains:mainfrom
github-actions[bot] wants to merge 60 commits intobestchains:mainfrom
Conversation
Signed-off-by: asararatnakar <asara.ratnakar@gmail.com> Signed-off-by: asararatnakar <asara.ratnakar@gmail.com>
Signed-off-by: asararatnakar <asara.ratnakar@gmail.com>
Signed-off-by: Josh Kneubuhl <jkneubuh@us.ibm.com>
…oes not take effect Signed-off-by: Abirdcfly <fp544037857@gmail.com>
Signed-off-by: Abirdcfly <fp544037857@gmail.com>
#109 Signed-off-by: Shoaeb Jindani <shoaebmjindani@gmail.com>
As per https://nvd.nist.gov/vuln/detail/CVE-2022-36109 Signed-off-by: Ben Smith <benjsmi@us.ibm.com>
#141 --------- Signed-off-by: asararatnakar <asara.ratnakar@gmail.com>
#143 Signed-off-by: asararatnakar <asara.ratnakar@gmail.com>
#143 Signed-off-by: asararatnakar <asara.ratnakar@gmail.com>
#148 --------- Signed-off-by: shoaebjindani <40020259+shoaebjindani@users.noreply.github.com> Co-authored-by: Shoaeb Jindani <jindani.shoaeb@ibm.com>
#154 Signed-off-by: asararatnakar <asara.ratnakar@gmail.com>
Fixes CVE-2023-44273. Signed-off-by: Ben Smith <benjsmi@us.ibm.com>
This PR addresses the renaming for the hsm configs Signed-off-by: asararatnakar <asara.ratnakar@gmail.com>
There was a major high vulnerability discovered in `github.com/docker/docker`, so, whether it is used for tests or actual production operation, we need to patch it in this project. See https://nvd.nist.gov/vuln/detail/CVE-2023-28842 Signed-off-by: Ben Smith <benjsmi@us.ibm.com>
#165 --------- Signed-off-by: asararatnakar <asara.ratnakar@gmail.com>
#164 --------- Signed-off-by: asararatnakar <asara.ratnakar@gmail.com>
Signed-off-by: asararatnakar <asara.ratnakar@gmail.com>
Changes to disable read and write permissions to the group user Signed-off-by: asararatnakar <asara.ratnakar@gmail.com>
Signed-off-by: asararatnakar <asara.ratnakar@gmail.com>
As per CVE-2024-24557. Signed-off-by: Ben Smith <benjsmi@us.ibm.com> Co-authored-by: Ratnakar <asara.ratnakar@gmail.com>
Related to #28 Signed-off-by: James Taylor <jamest@uk.ibm.com>
Signed-off-by: Ben Smith <benjsmi@us.ibm.com>
Signed-off-by: Ben Smith <benjsmi@us.ibm.com>
#192) Address newest docker/docker vulnerability. Signed-off-by: Ben Smith <benjsmi@us.ibm.com>
Signed-off-by: Shoaeb Jindani <jindani.shoaeb@ibm.com> Co-authored-by: Shoaeb Jindani <jindani.shoaeb@ibm.com>
Signed-off-by: MuthuSundaravadivel <muthu.infoavc@gmail.com>
Bump Go to 1.21.11. Note that starting with Go 1.21, the version in go.mod should be 3 digits. --------- Signed-off-by: David Enyeart <enyeart@us.ibm.com>
go-toolset doesn't have the latest versions of Go. Therefore use the ubi minimal image and install our preferred version of Go when building operator. --------- Signed-off-by: David Enyeart <enyeart@us.ibm.com> Co-authored-by: shoaebjindani <40020259+shoaebjindani@users.noreply.github.com>
Bump Go to 1.22.5. Latest Go also requires an update to controller-gen (otherwise it panics with a nil pointer). The controller-gen update in turn improves formatting of the generated CRD yaml files. Signed-off-by: David Enyeart <enyeart@us.ibm.com>
Update to the latest fabric (v2.5.9), fabric-ca, and fabric-lib-go.
These versions all depend on the same version of github.com/IBM/idemix
and
resolves issues related to breaking changes in github.com/IBM/idemix.
Note that the fabric dependency is now on the release-2.5 branch rather
than main branch,
which is why one of the function calls needed to be updated.
---------
Signed-off-by: David Enyeart <enyeart@us.ibm.com>
Co-authored-by: shoaebjindani <40020259+shoaebjindani@users.noreply.github.com>
updated dockerR to v26.1.5 as part of fix for CVE-2024-41110 Signed-off-by: Ketul Shah <shah.ketul@ibm.com>
New versions of gosec implemented stricter type conversion and bounds checks. This conversion is not vulnerable so we can suppress the warning. Signed-off-by: David Enyeart <enyeart@us.ibm.com>
Bump github.com/DataDog/zstd to v1.5.6. Signed-off-by: David Enyeart <enyeart@us.ibm.com>
Signed-off-by: Shoaeb Jindani <jindani.shoaeb@ibm.com> Co-authored-by: Shoaeb Jindani <jindani.shoaeb@ibm.com>
Signed-off-by: Shoaeb Jindani <jindani.shoaeb@ibm.com>
Signed-off-by: Shoaeb Jindani <shoaebjindani@gmail.com> Signed-off-by: Shoaeb Jindani <jindani.shoaeb@ibm.com>
Signed-off-by: Shoaeb Jindani <jindani.shoaeb@ibm.com>
Signed-off-by: Shoaeb Jindani <jindani.shoaeb@ibm.com>
…13 --> 1.5.14 for Fabric CA Signed-off-by: Shoaeb Jindani <jindani.shoaeb@ibm.com>
Bump golang.org/x/crypto v0.35.0. Signed-off-by: David Enyeart <enyeart@us.ibm.com>
Fixes CVE-2025-22868 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=2025-22868 --------- Signed-off-by: Shoaeb Jindani <jindani.shoaeb@ibm.com> Signed-off-by: shoaebjindani <40020259+shoaebjindani@users.noreply.github.com> Co-authored-by: Shoaeb Jindani <jindani.shoaeb@ibm.com>
Signed-off-by: Aviral Agrawal <aviralwal@users.noreply.github.com>
Signed-off-by: Aviral Agrawal <aviralwal@users.noreply.github.com>
…rom 1.5.…" This reverts commit c436d00.
Patch reported vulnerability for golang.org/x/net <v0.36 Signed-off-by: Thomas Leung <thomas.leung@ibm.com> Co-authored-by: Thomas Leung <thomas.leung@ibm.com>
### Fixes: - Update certificates in `orderer_test.go` and `peer_test.go` such that test can pass. - Update ginkgo test command since the old command is deprecated. - Fix typo ### Steps to update certificates (for reference) 1. Clone [fabric-samples](https://github.com/hyperledger/fabric-samples) repo 2. In the test-network-nano-bash folder, set `EnableNodeOUs` to `false` in `crypto-config.yaml` 3. Run `./generate_artifacts.sh` in test-network-nano-bash 4. The necessary certificates will be created in the crypto-config folder (convert the certificates to base64 and replace the old certificates as needed, I used orderer and orderer2 certs) Note: ibppeer3 has error during test is normal as one of the test is testing missing licence agreement. Signed-off-by: Thomas Leung <thomas.leung@ibm.com> Co-authored-by: Thomas Leung <thomas.leung@ibm.com>
Bump go to 1.24.3 Signed-off-by: Thomas Leung <thomas.leung@ibm.com> Co-authored-by: Thomas Leung <thomas.leung@ibm.com>
updated docker and grpc version Signed-off-by: Ketul Shah <shah.ketul@ibm.com>
Signed-off-by: Muthu Sundaravadivel <muthu@muthus-mbp.n3i-in.ibm.com> Co-authored-by: Muthu Sundaravadivel <muthu@muthus-mbp.n3i-in.ibm.com>
Signed-off-by: Muthu Sundaravadivel <muthu@muthus-mbp.n3i-in.ibm.com> Co-authored-by: Muthu Sundaravadivel <muthu@muthus-mbp.n3i-in.ibm.com>
Signed-off-by: Muthu Sundaravadivel <muthu@dhcp-9-90-36-56.n3i-in.ibm.com> Co-authored-by: Muthu Sundaravadivel <muthu@dhcp-9-90-36-56.n3i-in.ibm.com>
Signed-off-by: Shoaeb Jindani <jindani.shoaeb@ibm.com> Co-authored-by: Shoaeb Jindani <jindani.shoaeb@ibm.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
If there is a conflict, it is recommended to manually merge the conflicting commits, and then manually execute the sync github action.