Skip to content

Commit 634ef90

Browse files
committed
Add dependency update example for cherry-picks
Signed-off-by: Davanum Srinivas <[email protected]>
1 parent 78d4703 commit 634ef90

File tree

1 file changed

+3
-0
lines changed

1 file changed

+3
-0
lines changed

contributors/devel/sig-release/cherry-picks.md

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -62,6 +62,9 @@ your case by supplementing your PR with e.g.,
6262
- Key stakeholder SIG reviewers/approvers attesting to their confidence in the
6363
change being a required backport
6464

65+
To illustrate the point, dependency updates that just aim to silence some scanners
66+
and do not fix any vulnerable code are NOT eligible for cherry-picks.
67+
6568
If the change is in cloud provider-specific platform code (which is in the
6669
process of being moved out of core Kubernetes), describe the customer impact,
6770
how the issue escaped initial testing, remediation taken to prevent similar

0 commit comments

Comments
 (0)