Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

feat: add counter based ccc #1040

Merged
merged 51 commits into from
Sep 17, 2024

Conversation

0xmountaintop
Copy link

1. Purpose or design rationale of this PR

...

2. PR title

Your PR title must follow conventional commits (as we are doing squash merge for each PR), so it must start with one of the following types:

  • build: Changes that affect the build system or external dependencies (example scopes: yarn, eslint, typescript)
  • ci: Changes to our CI configuration files and scripts (example scopes: vercel, github, cypress)
  • docs: Documentation-only changes
  • feat: A new feature
  • fix: A bug fix
  • perf: A code change that improves performance
  • refactor: A code change that doesn't fix a bug, or add a feature, or improves performance
  • style: Changes that do not affect the meaning of the code (white-space, formatting, missing semi-colons, etc)
  • test: Adding missing tests or correcting existing tests

3. Deployment tag versioning

Has the version in params/version.go been updated?

  • This PR doesn't involve a new deployment, git tag, docker image tag, and it doesn't affect traces
  • Yes

4. Breaking change label

Does this PR have the breaking-change label?

  • This PR is not a breaking change
  • Yes

Copy link

semgrep-app bot commented Sep 13, 2024

Semgrep found 1 ssc-46663897-ab0c-04dc-126b-07fe2ce42fb2 finding:

Risk: Affected versions of golang.org/x/net, golang.org/x/net/http2, and net/http are vulnerable to Uncontrolled Resource Consumption. An attacker may cause an HTTP/2 endpoint to read arbitrary amounts of header data by sending an excessive number of CONTINUATION frames.

Fix: Upgrade this library to at least version 0.23.0 at go-ethereum/go.mod:147.

Reference(s): GHSA-4v7x-pqxf-cx7m, CVE-2023-45288

Ignore this finding from ssc-46663897-ab0c-04dc-126b-07fe2ce42fb2.

@0xmountaintop 0xmountaintop force-pushed the syncUpstream/counter_based_ccc branch 3 times, most recently from 70cde36 to df5f736 Compare September 16, 2024 10:26
@0xmountaintop 0xmountaintop force-pushed the syncUpstream/counter_based_ccc branch from 4e5e8e3 to 4680653 Compare September 17, 2024 01:12
@0xmountaintop 0xmountaintop marked this pull request as ready for review September 17, 2024 05:36
@0xmountaintop 0xmountaintop merged commit e0ba374 into syncUpstream/active Sep 17, 2024
6 of 7 checks passed
@0xmountaintop 0xmountaintop deleted the syncUpstream/counter_based_ccc branch September 17, 2024 06:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant