Argo Workflows - v3.4.17

Security

(2024-05-12)

  • 72efa2f15 chore(deps): bump github.com/cloudflare/circl to 1.3.7 to fix GHSA-9763-4f94-gfch (#12556)
  • 0f71a40db chore(deps): fixed medium CVE in github.com/docker/docker v24.0.0+incompatible (#12635)
  • 6030af483 chore(deps): upgrade Cosign to v2.2.3 (#12850)
  • cc258b874 build(deps): bump github.com/docker/docker from 24.0.0+incompatible to 24.0.9+incompatible (#12878)
  • 7e7d99b67 build(deps): bump github.com/go-jose/go-jose/v3 from 3.0.1 to 3.0.3 (#12879)
  • 6bb096efb chore(deps): bump express, follow-redirects, and webpack-dev-middleware (#12880)
  • a38cab742 chore(deps): bump undici from 5.28.3 to 5.28.4 in /ui (#12891)
  • ae8e2e526 fix: run linter on docs
  • d08a1c2f2 fix: linted typescript files
  • bf0174dba fix: insecureSkipVerify for GetUserInfoGroups (#12982)
  • 2df039b0b fix(ui): default to main container name in event source logs API call (#12939)
  • 0f3a00d7f fix(build): close pkg/apiclient/_.secondary.swagger.json (#12942)
  • f1af3263c fix: correct order in artifactGC error log message (#12935)
  • 627069692 fix: workflows that are retrying should not be deleted (Fixes #12636) (#12905)
  • caa339be2 fix: change fatal to panic. (#12931)
  • fb08ad044 fix: Correct log level for agent containers (#12929)
  • 30a756e9e fix(deps): upgrade x/net to v0.23.0. Fixes CVE-2023-45288 (#12921)
  • b0120579d fix(deps): upgrade http2 to v0.24. Fixes CVE-2023-45288 (#12901)
  • de840948c fix(deps): upgrade crypto from v0.20 to v0.22. Fixes CVE-2023-42818 (#12900)
  • aa2bd8f3e fix: use multipart upload method to put files larger than 5Gi to OSS. Fixes #12877 (#12897)
  • c5b4935fa fix: make sure Finalizers has chance to be removed. Fixes: #12836 (#12831)
  • 774388a7b fix(test): wait enough time to Trigger Running Hook. Fixes: #12844 (#12855)
  • 7821fdd0a fix: terminate workflow should not get throttled Fixes #12778 (#12792)
  • e0c16ff0f fix: pass dnsconfig to agent pod. Fixes: #12824 (#12825)
  • 82d14db2e fix(deps): upgrade undici from 5.28.2 to 5.28.3 due to CVE (#12763)
  • 9eb269d73 fix(deps): upgrade pgx from 4.18.1 to 4.18.2 due to CVE (#12753)
  • 6bd6a6373 fix: inline template loops should receive more than the first item. Fixes: #12594 (#12628)
  • 1f5bb49ce fix: workflow stuck in running state when using activeDeadlineSeconds on template level. Fixes: #12329 (#12761)
  • 1a259cb11 fix(ui): show correct podGC message for deleteDelayDuration. Fixes: #12395 (#12784)
  • 982038a88 fix(hack): various fixes & improvements to cherry-pick script (#12714)
  • c5ebbcf3a fix: make WF global parameters available in retries (#12698)
  • 56ff88e02 fix: find correct retry node when using templateRef. Fixes: #12633 (#12683)
  • 389492b4c fix: Patch taskset with subresources to delete completed node status.… (#12620)
  • 6194b8ada fix(typo): fix some typo (#12673)
  • 6cda00d2e fix(controller): re-allow changing executor args (#12609)
  • c590b2ef5 fix(controller): add missing namespace index from workflow informer (#12666)
  • 42ce47626 fix: pass through burst and qps for auth.kubeclient (#12575)
  • 4f8dd2ee7 fix: artifact subdir error when using volumeMount (#12638)
  • 3cd016b00 fix: Allow valueFrom in dag arguments parameters. Fixes #11900 (#11902)
  • c15a75b00 fix(resources): improve ressource accounting. Fixes #12468 (#12492)
  • 83a49b4b9 fix: upgrade expr-lang. Fixes #12037 (#12573)
  • bc7889be3 fix: make etcd errors transient (#12567)
  • b9a22f876 fix: update minio chart repo (#12552)
  • 574fd3ad2 fix: add resource quota evaluation timed out to transient (#12536)
  • 93e981d78 fix: prevent update race in workflow cache (Fixes #9574) (#12233)
  • 5f4845dbc fix: Fixed mutex with withSequence in http template broken. Fixes #12018 (#12176)
  • 790c0a4d1 fix: SSO with Jumpcloud "email_verified" field #12257 (#12318)
  • e1bb99c3c fix: wrong values are assigned to input parameters of workflowtemplat… (#12412)
  • c9ad89985 fix: http template host header rewrite(#12385) (#12386)
  • e6ea4b147 fix: ensure workflow wait for onExit hook for DAG template (#11880) (#12436)
  • 7db24e009 fix: move log with potential sensitive data to debug loglevel. Fixes: #12366 (#12368)
  • 9540f8e0f fix: resolve output artifact of steps from expression when it refers … (#12320)
  • adf368514 fix: delete pending pod when workflow terminated (#12196)
  • fedfb3790 fix: create dir when input path is not exist in oss (#12323)
  • a68e1f053 fix: return failed instead of success when no container status (#12197)
  • eb9bbc8aa fix: Changes to workflow semaphore does work #12194 (#12284)
  • 731366411 fix: properly resolve exit handler inputs (fixes #12283) (#12288)
  • 58418906f fix: Add identifiable user agent in API client. Fixes #11996 (#12276)
  • d6c5ed078 fix: remove deprecated function rand.Seed (#12271)
  • 732b94a73 fix: leak stream (#12193)
  • 6daa22b08 fix(server): allow passing loglevels as env vars to Server (#12145)
  • e8e9c2a48 fix: retry S3 on RequestError. Fixes #9914 (#12191)
  • 18685ad8d fix: Fix the Maximum Recursion Depth prompt link in the CLI. (#12015)
  • 88d4e0f14 fix: Only append slash when missing for Artifactory repoURL (#11812)
  • 4627aa047 fix: upgrade module for pull image in google cloud issue #9630 (#11614)
  • 2368b37e6 fix: Upgrade Go to v1.21 Fixes #11556 (#11601)
  • 63af1c414 fix(ui): ensure package.json#name is not the same as argo-ui (#11595)
  • c9f96f446 fix: Devcontainer resets /etc/hosts (#11439) (#11440)
  • b23713e4b fix: make archived logs more human friendly in UI (#11420)
  • 660bbb68f fix: Live workflow takes precedence during merge to correctly display in the UI (#11336)
  • a4ca4d27e fix: add space to fix release action issue (#11160)
  • 5fe8b37a6 fix: upgrade argo-ui components to latest (3.4 backport) (#12998)

Contributors

  • Alan Clucas
  • AlbeeSo
  • AloysAqemia
  • Andrei Shevchenko
  • Anton Gilgur
  • Bryce-Huang
  • Byeonggon Lee
  • Dennis Lawler
  • Denys Melnyk
  • Eduardo Rodrigues
  • Helge Willum Thingvad
  • Isitha Subasinghe
  • João Pedro
  • Raffael
  • Ruin09
  • Ryan Currah
  • Shiwei Tang
  • Shunsuke Suzuki
  • Son Bui
  • Tal Yitzhak
  • Tianchu Zhao
  • Weidong Cai
  • Yang Lu
  • Yuan (Terry) Tang
  • Yuan Tang
  • Yulin Li
  • dependabot[bot]
  • guangwu
  • gussan
  • ivancili
  • jiangjiang
  • jswxstw
  • junkmm
  • neosu
  • shuangkun tian
  • static-moonlight
  • sycured

Details

date
May 12, 2024, midnight
name
v3.4.17
type
Patch
👇
Register or login to:
  • 🔍View and search all Argo Workflows releases.
  • 🛠️Create and share lists to track your tools.
  • 🚨Setup notifications for major, security, feature or patch updates.
  • 🚀Much more coming soon!
Continue with GitHub
Continue with Google
or