Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade Alpine to 3.18 #5684

Merged
merged 2 commits into from
Nov 30, 2023
Merged

Upgrade Alpine to 3.18 #5684

merged 2 commits into from
Nov 30, 2023

Conversation

dsabsay
Copy link
Contributor

@dsabsay dsabsay commented Nov 29, 2023

What this PR does:

Upgrades Alpine to 3.18. Intended to fix several security vulnerabilities in alpine packages. In particular, Jfrog Xray is flagging CVE-2022-48174. I'm unsure if it's correct, as the image has the latest busybox in 3.17. Regardless, it's much easier to upgrade to keep scans clean instead of tracking various false positives. I have some 3.18 images and this vuln does not show up.

Which issue(s) this PR fixes:
None

Checklist

  • Tests updated
  • Documentation added
  • CHANGELOG.md updated - the order of entries should be [CHANGE], [FEATURE], [ENHANCEMENT], [BUGFIX]

Signed-off-by: Daniel Sabsay <[email protected]>
Signed-off-by: Daniel Sabsay <[email protected]>
@yeya24
Copy link
Contributor

yeya24 commented Nov 29, 2023

Hi @dsabsay, can you please add more description to the pr itself, what does this change fix? Thanks

@dsabsay
Copy link
Contributor Author

dsabsay commented Nov 29, 2023

@yeya24 Added.

@alanprot
Copy link
Member

LGTM

@yeya24 yeya24 merged commit 88a7b7c into cortexproject:master Nov 30, 2023
yeya24 pushed a commit to yeya24/cortex that referenced this pull request Apr 23, 2024
* Upgrade Alpine to 3.18

Signed-off-by: Daniel Sabsay <[email protected]>

* Update CHANGELOG.md

Signed-off-by: Daniel Sabsay <[email protected]>

---------

Signed-off-by: Daniel Sabsay <[email protected]>
Co-authored-by: Daniel Sabsay <[email protected]>
friedrichg added a commit that referenced this pull request Apr 24, 2024
* Upgrade Alpine to 3.18 (#5684)

* Upgrade Alpine to 3.18

Signed-off-by: Daniel Sabsay <[email protected]>

* Update CHANGELOG.md

Signed-off-by: Daniel Sabsay <[email protected]>

---------

Signed-off-by: Daniel Sabsay <[email protected]>
Co-authored-by: Daniel Sabsay <[email protected]>

* Upgrade to go 1.21.9 (#5879)

* Upgrade to go 1.21.9

Signed-off-by: Friedrich Gonzalez <[email protected]>

* Update changelog and workflows

Signed-off-by: Friedrich Gonzalez <[email protected]>

* Not use minor version for now. Needs more investigation

Signed-off-by: Friedrich Gonzalez <[email protected]>

* Update image again

Signed-off-by: Friedrich Gonzalez <[email protected]>

---------

Signed-off-by: Friedrich Gonzalez <[email protected]>

* fix go version for integration tests (#5882)

Signed-off-by: Friedrich Gonzalez <[email protected]>

* include #5882 to changelog

Signed-off-by: Ben Ye <[email protected]>

try fixing lint

Signed-off-by: Ben Ye <[email protected]>

try again

Signed-off-by: Ben Ye <[email protected]>

---------

Signed-off-by: Daniel Sabsay <[email protected]>
Signed-off-by: Friedrich Gonzalez <[email protected]>
Signed-off-by: Ben Ye <[email protected]>
Co-authored-by: Daniel Sabsay <[email protected]>
Co-authored-by: Daniel Sabsay <[email protected]>
Co-authored-by: Friedrich Gonzalez <[email protected]>
yeya24 added a commit that referenced this pull request Apr 25, 2024
* Cherrypick commits for 1.16.1 (#5885)

* Upgrade Alpine to 3.18 (#5684)

* Upgrade Alpine to 3.18

Signed-off-by: Daniel Sabsay <[email protected]>

* Update CHANGELOG.md

Signed-off-by: Daniel Sabsay <[email protected]>

---------

Signed-off-by: Daniel Sabsay <[email protected]>
Co-authored-by: Daniel Sabsay <[email protected]>

* Upgrade to go 1.21.9 (#5879)

* Upgrade to go 1.21.9

Signed-off-by: Friedrich Gonzalez <[email protected]>

* Update changelog and workflows

Signed-off-by: Friedrich Gonzalez <[email protected]>

* Not use minor version for now. Needs more investigation

Signed-off-by: Friedrich Gonzalez <[email protected]>

* Update image again

Signed-off-by: Friedrich Gonzalez <[email protected]>

---------

Signed-off-by: Friedrich Gonzalez <[email protected]>

* fix go version for integration tests (#5882)

Signed-off-by: Friedrich Gonzalez <[email protected]>

* include #5882 to changelog

Signed-off-by: Ben Ye <[email protected]>

try fixing lint

Signed-off-by: Ben Ye <[email protected]>

try again

Signed-off-by: Ben Ye <[email protected]>

---------

Signed-off-by: Daniel Sabsay <[email protected]>
Signed-off-by: Friedrich Gonzalez <[email protected]>
Signed-off-by: Ben Ye <[email protected]>
Co-authored-by: Daniel Sabsay <[email protected]>
Co-authored-by: Daniel Sabsay <[email protected]>
Co-authored-by: Friedrich Gonzalez <[email protected]>

* update changelog

Signed-off-by: Ben Ye <[email protected]>

---------

Signed-off-by: Daniel Sabsay <[email protected]>
Signed-off-by: Friedrich Gonzalez <[email protected]>
Signed-off-by: Ben Ye <[email protected]>
Co-authored-by: Daniel Sabsay <[email protected]>
Co-authored-by: Daniel Sabsay <[email protected]>
Co-authored-by: Friedrich Gonzalez <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants