Skip to content

Conversation

dependency-envoy[bot]
Copy link
Contributor

@dependency-envoy dependency-envoy bot commented Sep 30, 2025

Resolve a couple of CVEs (CVE-2025-27817, CVE-2025-27818) that most likely dont affect us but are showing up in our scanner

Signed-off-by: dependency-envoy[bot] <148525496+dependency-envoy[bot]@users.noreply.github.com>

@repokitteh-read-only repokitteh-read-only bot added the deps Approval required for changes to Envoy's external dependencies label Sep 30, 2025
Copy link

CC @envoyproxy/dependency-shepherds: Your approval is needed for changes made to (bazel/.*repos.*\.bzl)|(bazel/dependency_imports\.bzl)|(api/bazel/.*\.bzl)|(.*/requirements\.txt)|(.*\.patch).
envoyproxy/dependency-shepherds assignee is @RyanTheOptimist

🐱

Caused by: #41287 was opened by dependency-envoy[bot].

see: more, trace.

Signed-off-by: dependency-envoy[bot] <148525496+dependency-envoy[bot]@users.noreply.github.com>
@phlax phlax force-pushed the dependency/bazel/kafka_source/3.9.1 branch from 34716d1 to f7336a1 Compare September 30, 2025 13:51
@phlax phlax changed the title deps: Bump kafka_source -> 3.9.1 deps: Bump kafka_source (+kafka_server_binary) -> 3.9.1 Sep 30, 2025
@phlax
Copy link
Member

phlax commented Sep 30, 2025

cc @adamkotwasinski seems like even trying to bump to this version is throwing errors

 In file included from contrib/kafka/filters/network/source/mesh/command_handlers/produce.cc:3:
bazel-out/k8-opt/bin/contrib/kafka/filters/network/source/external/responses.h:15367:8: error: redefinition of 'Listener'
 15367 | struct Listener {
       |        ^
bazel-out/k8-opt/bin/contrib/kafka/filters/network/source/external/requests.h:17834:8: note: previous definition is here
 17834 | struct Listener {
       |        ^
In file included from contrib/kafka/filters/network/source/mesh/command_handlers/produce.cc:3:
bazel-out/k8-opt/bin/contrib/kafka/filters/network/source/external/responses.h:19287:8: error: redefinition of 'StateBatch'
 19287 | struct StateBatch {
       |        ^
bazel-out/k8-opt/bin/contrib/kafka/filters/network/source/external/requests.h:18420:8: note: previous definition is here
 18420 | struct StateBatch {
       |        ^
In file included from contrib/kafka/filters/network/source/mesh/command_handlers/produce.cc:3:
bazel-out/k8-opt/bin/contrib/kafka/filters/network/source/external/responses.h:19316:7: error: redefinition of 'StateBatchV0Deserializer'
 19316 | class StateBatchV0Deserializer:
       |       ^
bazel-out/k8-opt/bin/contrib/kafka/filters/network/source/external/requests.h:18449:7: note: previous definition is here
 18449 | class StateBatchV0Deserializer:
       |       ^
3 errors generated.

Signed-off-by: Ryan Northey <[email protected]>
@phlax phlax requested a review from mattklein123 as a code owner October 7, 2025 10:50
Signed-off-by: Ryan Northey <[email protected]>
@phlax phlax force-pushed the dependency/bazel/kafka_source/3.9.1 branch from af68ff8 to bd6079f Compare October 7, 2025 12:48
Copy link
Member

@agrawroh agrawroh left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, Thanks!

@repokitteh-read-only repokitteh-read-only bot removed the deps Approval required for changes to Envoy's external dependencies label Oct 7, 2025
@phlax phlax merged commit dd3cbce into main Oct 7, 2025
25 checks passed
phlax pushed a commit to phlax/envoy that referenced this pull request Oct 8, 2025
…xy#41287)

Resolve a couple of CVEs (CVE-2025-27817, CVE-2025-27818) that most
likely dont affect us but are showing up in our scanner

Signed-off-by: dependency-envoy[bot] <148525496+dependency-envoy[bot]@users.noreply.github.com>
Signed-off-by: Ryan Northey <[email protected]>
phlax pushed a commit to phlax/envoy that referenced this pull request Oct 8, 2025
…xy#41287)

Resolve a couple of CVEs (CVE-2025-27817, CVE-2025-27818) that most
likely dont affect us but are showing up in our scanner

Signed-off-by: dependency-envoy[bot] <148525496+dependency-envoy[bot]@users.noreply.github.com>
Signed-off-by: Ryan Northey <[email protected]>
phlax pushed a commit to phlax/envoy that referenced this pull request Oct 8, 2025
…xy#41287)

Resolve a couple of CVEs (CVE-2025-27817, CVE-2025-27818) that most
likely dont affect us but are showing up in our scanner

Signed-off-by: dependency-envoy[bot] <148525496+dependency-envoy[bot]@users.noreply.github.com>
Signed-off-by: Ryan Northey <[email protected]>
phlax pushed a commit to phlax/envoy that referenced this pull request Oct 8, 2025
…xy#41287)

Resolve a couple of CVEs (CVE-2025-27817, CVE-2025-27818) that most
likely dont affect us but are showing up in our scanner

Signed-off-by: dependency-envoy[bot] <148525496+dependency-envoy[bot]@users.noreply.github.com>
Signed-off-by: Ryan Northey <[email protected]>
phlax pushed a commit that referenced this pull request Oct 8, 2025
Resolve a couple of CVEs (CVE-2025-27817, CVE-2025-27818) that most
likely dont affect us but are showing up in our scanner

Signed-off-by: dependency-envoy[bot] <148525496+dependency-envoy[bot]@users.noreply.github.com>
Signed-off-by: Ryan Northey <[email protected]>
phlax pushed a commit that referenced this pull request Oct 8, 2025
Resolve a couple of CVEs (CVE-2025-27817, CVE-2025-27818) that most
likely dont affect us but are showing up in our scanner

Signed-off-by: dependency-envoy[bot] <148525496+dependency-envoy[bot]@users.noreply.github.com>
Signed-off-by: Ryan Northey <[email protected]>
phlax pushed a commit that referenced this pull request Oct 8, 2025
Resolve a couple of CVEs (CVE-2025-27817, CVE-2025-27818) that most
likely dont affect us but are showing up in our scanner

Signed-off-by: dependency-envoy[bot] <148525496+dependency-envoy[bot]@users.noreply.github.com>
Signed-off-by: Ryan Northey <[email protected]>
phlax pushed a commit that referenced this pull request Oct 8, 2025
Resolve a couple of CVEs (CVE-2025-27817, CVE-2025-27818) that most
likely dont affect us but are showing up in our scanner

Signed-off-by: dependency-envoy[bot] <148525496+dependency-envoy[bot]@users.noreply.github.com>
Signed-off-by: Ryan Northey <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants