Skip to content

release-8.5: add dependency security fixes to v8.5.8 release notes (#21913) - #21934

Open
ti-chi-bot wants to merge 3 commits into
pingcap:masterfrom
ti-chi-bot:cherry-pick-21913-to-master
Open

ti-chi-bot wants to merge 3 commits into
pingcap:masterfrom
ti-chi-bot:cherry-pick-21913-to-master

Conversation

@ti-chi-bot

@ti-chi-bot ti-chi-bot commented Sep 15, 2026

Copy link
Copy Markdown
Member

This is an automated cherry-pick of #21913

What is changed, added or deleted? (Required)

  • Add TiKV, TiCDC, and DM dependency security updates to the TiDB 8.5.8 release notes
  • Add the TiCDC Grafana build information fix
  • Group related TiCDC dependency updates into one user-facing entry while preserving the source issue and PR references

Which TiDB version(s) do your changes apply to? (Required)

  • master (the latest development version)
  • v8.5 (TiDB 8.5 versions)
  • v8.4 (TiDB 8.4 versions)
  • v8.3 (TiDB 8.3 versions)
  • v8.2 (TiDB 8.2 versions)
  • v8.1 (TiDB 8.1 versions)
  • v7.5 (TiDB 7.5 versions)
  • v7.1 (TiDB 7.1 versions)
  • v6.5 (TiDB 6.5 versions)

What is the related PR or file link(s)?

AI agent involvement

  • The changes in this PR were primarily made by an AI agent on behalf of the PR author.

Do your changes match any of the following descriptions?

  • Delete files
  • Change aliases
  • Need modification after applied to another branch
  • Might cause conflicts after applied to another branch

Summary by CodeRabbit

  • 安全修复
    • 更新 TiCDC、TiKV 和 DM 使用的相关依赖,修复潜在的已知安全漏洞。
    • 修复 PD 指标查询接口存在的服务器端请求伪造(SSRF)风险。
    • 升级 TiDB、OpenTelemetry、AWS SDK、Rust 及其他相关组件依赖,提升系统整体安全性。

@ti-chi-bot ti-chi-bot added lgtm size/XS Denotes a PR that changes 0-9 lines, ignoring generated files. type/cherry-pick-for-master This PR is cherry-picked to master from a source PR. labels Sep 15, 2026
@ti-chi-bot

ti-chi-bot Bot commented Sep 15, 2026

Copy link
Copy Markdown

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by:
Once this PR has been reviewed and has the lgtm label, please assign tangenta for approval. For more information see the Code Review Process.
Please ensure that each of them provides their approval before proceeding.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@coderabbitai

coderabbitai Bot commented Sep 15, 2026

Copy link
Copy Markdown

Review Change StackReview Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: d8303494-a85d-4440-94db-9a3f53be6259

📥 Commits

Reviewing files that changed from the base of the PR and between 924e58f and 71bc30e.

📒 Files selected for processing (1)
  • releases/release-8.5.8.md

Included review availability: Your plan provides up to 4 included reviews per hour; 3 remain after this review.


📝 Walkthrough

Walkthrough

本次更新修改 release-8.5.8.md,新增 TiCDC、TiKV 和 DM 的依赖安全修复记录,并为 PD 的 SSRF 修复条目补充 issue 链接。

Changes

安全修复发布说明

Layer / File(s) Summary
依赖安全修复记录
releases/release-8.5.8.md
新增 TiCDC、TiKV 和 DM 的依赖升级安全修复条目。
PD SSRF 修复链接
releases/release-8.5.8.md
/metric/query/metric/query_range 修复条目补充 issue #11081 链接。

Priority: ⬇️ Low

Estimated code review effort: 1 (Trivial) | ~5 minutes

Change: Other

Merge Risk: ⚪ Minimal · up to 71bc3

This documentation-only change has no identified runtime or operational impact and is ready to merge.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed 标题明确概括了主要变更,即为 v8.5.8 发布说明添加依赖安全修复记录。
Description check ✅ Passed 描述包含变更内容、适用版本、相关链接、AI agent 参与情况和变更类型检查项。v8.5 版本已正确勾选,内容与 PR 目标一致。
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

lgtm size/XS Denotes a PR that changes 0-9 lines, ignoring generated files. type/cherry-pick-for-master This PR is cherry-picked to master from a source PR.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants