Skip to content

Commit deab151

Browse files
authored
Merge pull request #7517 from dims/add-dependency-update-example-for-cherry-picks
Add dependency update example for cherry-picks
2 parents 78d4703 + 634ef90 commit deab151

File tree

1 file changed

+3
-0
lines changed

1 file changed

+3
-0
lines changed

contributors/devel/sig-release/cherry-picks.md

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -62,6 +62,9 @@ your case by supplementing your PR with e.g.,
6262
- Key stakeholder SIG reviewers/approvers attesting to their confidence in the
6363
change being a required backport
6464

65+
To illustrate the point, dependency updates that just aim to silence some scanners
66+
and do not fix any vulnerable code are NOT eligible for cherry-picks.
67+
6568
If the change is in cloud provider-specific platform code (which is in the
6669
process of being moved out of core Kubernetes), describe the customer impact,
6770
how the issue escaped initial testing, remediation taken to prevent similar

0 commit comments

Comments
 (0)