Commit Graph

5 Commits (ent-changelog-1.18.6)

Author SHA1 Message Date
hc-github-team-consul-core 5f83df637d
Backport of security: enable go stdlib scans into release/1.18.x (#21211)
* backport of commit 00ad74d146

* backport of commit 0401151cfc

* backport of commit 700e0aec84

---------

Co-authored-by: dduzgun-security <deniz.duzgun@hashicorp.com>
Co-authored-by: Deniz Onur Duzgun <59659739+dduzgun-security@users.noreply.github.com>
2024-05-23 14:25:13 -04:00
hc-github-team-consul-core a15c9c3d01
Backport of [NET-8601] security: upgrade vault/api to remove go-jose.v2 into release/1.18.x (#21053)
backport of commit 1c8e398d09

Co-authored-by: Michael Zalimeni <michael.zalimeni@hashicorp.com>
2024-05-14 08:41:47 -04:00
hc-github-team-consul-core 97e1621d43
Backport of security: ignore test and internal tool modules into release/1.18.x (#20972)
backport of commit fdf3f9b275

Co-authored-by: Michael Zalimeni <michael.zalimeni@hashicorp.com>
2024-04-08 21:58:17 +00:00
hc-github-team-consul-core 3171fd84cb
Backport of security: triage false positive for go-jose/v3 into release/1.18.x (#20906)
backport of commit c8d6b2528c

Co-authored-by: Michael Zalimeni <michael.zalimeni@hashicorp.com>
2024-03-26 21:53:34 +00:00
Michael Zalimeni d0bc091a60
[NET-6969] security: Re-enable Go Module + secrets security scans for release branches (#19978)
* security: re-enable security scan release block

This was previously disabled due to an unresolved false-positive CVE.
Re-enabling both secrets and OSV + Go Modules scanning, which per our
current scan results should not be a blocker to future releases.

* security: run security scans on main and release branches
2023-12-21 15:11:05 +00:00