-
Notifications
You must be signed in to change notification settings - Fork 792
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[release-1.15] CVE-2024-3727, bump to v1.15.1 #2329
[release-1.15] CVE-2024-3727, bump to v1.15.1 #2329
Conversation
Addresses CVE-2024-3727 https://issues.redhat.com/browse/RHEL-35443 https://issues.redhat.com/browse/RHEL-35440 Signed-off-by: tomsweeneyredhat <tsweeney@redhat.com>
Ephemeral COPR build failed. @containers/packit-build please check. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks!
@TomSweeneyRedHat The failing tests can probably be fixed by a backport of #2280 . |
... at Fedora 38 because the tests are assuming a v2s2 image, but as of Fedora 39, the image uses the OCI format. Signed-off-by: Miloslav Trmač <mitr@redhat.com> Signed-off-by: tomsweeneyredhat <tsweeney@redhat.com>
Bump the release to v1.15.1 to prepare the fix for CVE-2024-3727 Signed-off-by: tomsweeneyredhat <tsweeney@redhat.com>
20d3639
to
e2ea426
Compare
Thanks @mtrmac ! I've just cherry picked that , sorted the commits and repushed. 🤞 |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks!
Also addresses: https://issues.redhat.com/browse/OCPBUGS-33267 |
Addresses CVE-2024-3727
https://issues.redhat.com/browse/RHEL-35443
https://issues.redhat.com/browse/RHEL-35440