Skip to content

chore(deps): Bump github.com/rclone/rclone from 1.69.3 to 1.74.0#18833

Closed
orgads wants to merge 1 commit into
influxdata:masterfrom
orgads:rclone-up
Closed

chore(deps): Bump github.com/rclone/rclone from 1.69.3 to 1.74.0#18833
orgads wants to merge 1 commit into
influxdata:masterfrom
orgads:rclone-up

Conversation

@orgads
Copy link
Copy Markdown
Contributor

@orgads orgads commented May 3, 2026

Summary

Fixes critical CVE-2026-41176.

Checklist

Related issues

resolves #18832 (do we really need an issue for this kind of updates?)
closes #17535.

@telegraf-tiger telegraf-tiger Bot added the chore label May 3, 2026
@orgads orgads force-pushed the rclone-up branch 3 times, most recently from 5d04c1d to 08136f5 Compare May 3, 2026 15:50
Fixes critical CVE-2026-41176.

Adapt remotefile output to rclone's migration from logrus to log/slog:
fs.LogOutput was removed and replaced by fs/log.Handler.SetOutput.

resolves influxdata#18832.
closes influxdata#17535.
@telegraf-tiger
Copy link
Copy Markdown
Contributor

telegraf-tiger Bot commented May 4, 2026

Download PR build artifacts for linux_amd64.tar.gz, darwin_arm64.tar.gz, and windows_amd64.zip.
Downloads for additional architectures and packages are available below.

⚠️ This pull request increases the Telegraf binary size by 1.09 % for linux amd64 (new size: 307.9 MB, nightly size 304.6 MB)

📦 Click here to get additional PR build artifacts

Artifact URLs

. DEB . RPM . TAR . GZ . ZIP
amd64.deb aarch64.rpm darwin_amd64.tar.gz windows_amd64.zip
arm64.deb armel.rpm darwin_arm64.tar.gz windows_arm64.zip
armel.deb armv6hl.rpm freebsd_amd64.tar.gz windows_i386.zip
armhf.deb i386.rpm freebsd_armv7.tar.gz
i386.deb ppc64le.rpm freebsd_i386.tar.gz
mips.deb riscv64.rpm linux_amd64.tar.gz
mipsel.deb s390x.rpm linux_arm64.tar.gz
ppc64el.deb x86_64.rpm linux_armel.tar.gz
riscv64.deb linux_armhf.tar.gz
s390x.deb linux_i386.tar.gz
linux_mips.tar.gz
linux_mipsel.tar.gz
linux_ppc64le.tar.gz
linux_riscv64.tar.gz
linux_s390x.tar.gz

@srebhan
Copy link
Copy Markdown
Member

srebhan commented May 4, 2026

@orgads please check #17535! We need rclone/rclone#8908 merged first otherwise Telegraf will hang as soon as you log the first message through slog! Therefore I'm closing this PR.

@srebhan srebhan closed this May 4, 2026
@orsher
Copy link
Copy Markdown

orsher commented May 10, 2026

Seems like rclone/rclone#8908 was merged.
Is it part of the rclone latest version? Can we update this pr / create a new one?

@Roberttmoon
Copy link
Copy Markdown

Roberttmoon commented May 11, 2026

Sadly it looks like 1.74.1 does not the includes the work from rclone/rclone#8908.

Looks like we are still waiting

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

rclone dependency has a critical CVE

4 participants