Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade Alpine to 3.18 #5684

Merged
merged 2 commits into from
Nov 30, 2023
Merged

Upgrade Alpine to 3.18 #5684

merged 2 commits into from
Nov 30, 2023

Conversation

dsabsay
Copy link
Contributor

@dsabsay dsabsay commented Nov 29, 2023

What this PR does:

Upgrades Alpine to 3.18. Intended to fix several security vulnerabilities in alpine packages. In particular, Jfrog Xray is flagging CVE-2022-48174. I'm unsure if it's correct, as the image has the latest busybox in 3.17. Regardless, it's much easier to upgrade to keep scans clean instead of tracking various false positives. I have some 3.18 images and this vuln does not show up.

Which issue(s) this PR fixes:
None

Checklist

  • Tests updated
  • Documentation added
  • CHANGELOG.md updated - the order of entries should be [CHANGE], [FEATURE], [ENHANCEMENT], [BUGFIX]

Signed-off-by: Daniel Sabsay <sabsay@adobe.com>
Signed-off-by: Daniel Sabsay <sabsay@adobe.com>
@yeya24
Copy link
Contributor

yeya24 commented Nov 29, 2023

Hi @dsabsay, can you please add more description to the pr itself, what does this change fix? Thanks

@dsabsay
Copy link
Contributor Author

dsabsay commented Nov 29, 2023

@yeya24 Added.

@alanprot
Copy link
Member

LGTM

@yeya24 yeya24 merged commit 88a7b7c into cortexproject:master Nov 30, 2023
14 checks passed
yeya24 pushed a commit to yeya24/cortex that referenced this pull request Apr 23, 2024
* Upgrade Alpine to 3.18

Signed-off-by: Daniel Sabsay <sabsay@adobe.com>

* Update CHANGELOG.md

Signed-off-by: Daniel Sabsay <sabsay@adobe.com>

---------

Signed-off-by: Daniel Sabsay <sabsay@adobe.com>
Co-authored-by: Daniel Sabsay <sabsay@adobe.com>
friedrichg added a commit that referenced this pull request Apr 24, 2024
* Upgrade Alpine to 3.18 (#5684)

* Upgrade Alpine to 3.18

Signed-off-by: Daniel Sabsay <sabsay@adobe.com>

* Update CHANGELOG.md

Signed-off-by: Daniel Sabsay <sabsay@adobe.com>

---------

Signed-off-by: Daniel Sabsay <sabsay@adobe.com>
Co-authored-by: Daniel Sabsay <sabsay@adobe.com>

* Upgrade to go 1.21.9 (#5879)

* Upgrade to go 1.21.9

Signed-off-by: Friedrich Gonzalez <friedrichg@gmail.com>

* Update changelog and workflows

Signed-off-by: Friedrich Gonzalez <friedrichg@gmail.com>

* Not use minor version for now. Needs more investigation

Signed-off-by: Friedrich Gonzalez <friedrichg@gmail.com>

* Update image again

Signed-off-by: Friedrich Gonzalez <friedrichg@gmail.com>

---------

Signed-off-by: Friedrich Gonzalez <friedrichg@gmail.com>

* fix go version for integration tests (#5882)

Signed-off-by: Friedrich Gonzalez <friedrichg@gmail.com>

* include #5882 to changelog

Signed-off-by: Ben Ye <benye@amazon.com>

try fixing lint

Signed-off-by: Ben Ye <benye@amazon.com>

try again

Signed-off-by: Ben Ye <benye@amazon.com>

---------

Signed-off-by: Daniel Sabsay <sabsay@adobe.com>
Signed-off-by: Friedrich Gonzalez <friedrichg@gmail.com>
Signed-off-by: Ben Ye <benye@amazon.com>
Co-authored-by: Daniel Sabsay <danielrsabsay@gmail.com>
Co-authored-by: Daniel Sabsay <sabsay@adobe.com>
Co-authored-by: Friedrich Gonzalez <friedrichg@gmail.com>
yeya24 added a commit that referenced this pull request Apr 25, 2024
* Cherrypick commits for 1.16.1 (#5885)

* Upgrade Alpine to 3.18 (#5684)

* Upgrade Alpine to 3.18

Signed-off-by: Daniel Sabsay <sabsay@adobe.com>

* Update CHANGELOG.md

Signed-off-by: Daniel Sabsay <sabsay@adobe.com>

---------

Signed-off-by: Daniel Sabsay <sabsay@adobe.com>
Co-authored-by: Daniel Sabsay <sabsay@adobe.com>

* Upgrade to go 1.21.9 (#5879)

* Upgrade to go 1.21.9

Signed-off-by: Friedrich Gonzalez <friedrichg@gmail.com>

* Update changelog and workflows

Signed-off-by: Friedrich Gonzalez <friedrichg@gmail.com>

* Not use minor version for now. Needs more investigation

Signed-off-by: Friedrich Gonzalez <friedrichg@gmail.com>

* Update image again

Signed-off-by: Friedrich Gonzalez <friedrichg@gmail.com>

---------

Signed-off-by: Friedrich Gonzalez <friedrichg@gmail.com>

* fix go version for integration tests (#5882)

Signed-off-by: Friedrich Gonzalez <friedrichg@gmail.com>

* include #5882 to changelog

Signed-off-by: Ben Ye <benye@amazon.com>

try fixing lint

Signed-off-by: Ben Ye <benye@amazon.com>

try again

Signed-off-by: Ben Ye <benye@amazon.com>

---------

Signed-off-by: Daniel Sabsay <sabsay@adobe.com>
Signed-off-by: Friedrich Gonzalez <friedrichg@gmail.com>
Signed-off-by: Ben Ye <benye@amazon.com>
Co-authored-by: Daniel Sabsay <danielrsabsay@gmail.com>
Co-authored-by: Daniel Sabsay <sabsay@adobe.com>
Co-authored-by: Friedrich Gonzalez <friedrichg@gmail.com>

* update changelog

Signed-off-by: Ben Ye <benye@amazon.com>

---------

Signed-off-by: Daniel Sabsay <sabsay@adobe.com>
Signed-off-by: Friedrich Gonzalez <friedrichg@gmail.com>
Signed-off-by: Ben Ye <benye@amazon.com>
Co-authored-by: Daniel Sabsay <danielrsabsay@gmail.com>
Co-authored-by: Daniel Sabsay <sabsay@adobe.com>
Co-authored-by: Friedrich Gonzalez <friedrichg@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants