v0.31.3 Release 🎉
This is a patch release addressing a security issue on the golang.org/x/net and github.com/grpc/grpc-go dependency:
- HTTP/2 rapid reset can cause excessive work in net/http - commits
- This addresses GHSA-qppj-fm5r-hxr3 by not allowing more server handlers to be run than the HTTP/2 MAX_CONCURRENT_STREAMS setting.
ChangeLog 📋
Misc 🔨
- Bump tektoncd/pipeline to v0.47.5 e26d96a
- Bump hub to v1.13.2 6077d23
- Bump chains to v0.16.1 2f4ab15