-
Notifications
You must be signed in to change notification settings - Fork 602
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[TASK] Fix CVE issues for v1.7.0 (RC1) #8976
Comments
Analyse RC1Longhorn Componentslonghornio/backing-image-manager:v1.7.0-rc1
Action: won't fix. longhornio/longhorn-engine:v1.7.0-rc1
Action: update dependencies. longhornio/longhorn-instance-manager:v1.7.0-rc1
Action: update dependencies. longhornio/longhorn-manager:v1.7.0-rc1
The Action: won't fix. longhornio/longhorn-share-manager:v1.7.0-rc1
Action: won't fix. longhornio/longhorn-ui:v1.7.0-rc1
Action: won't fix. longhornio/support-bundle-kit:v0.0.39
Action: release v0.0.40. External Componentslonghornio/csi-attacher:v4.5.1
Action: update to the current highest available minor version: longhornio/csi-provisioner:v4.0.1
The current highest available minor version upstream: Action: won't fix. longhornio/csi-resizer:v1.10.1
Action: update to the current highest available minor version: longhornio/csi-snapshotter:v7.0.2
The current highest available minor version upstream: Action: won't fix. longhornio/csi-node-driver-registrar:v2.9.2
Action: update to the current highest available minor version: longhornio/livenessprobe:v2.12.0
The current highest available minor version upstream: Action: won't fix. longhornio/openshift-origin-oauth-proxy:4.14
Action: not in scope, we can update to the suggested version: |
@derekbit , @mantissahz , is this within our scope for CVE? cc @innobead |
We just mirrored it from https://quay.io/repository/openshift/origin-oauth-proxy?tab=tags and I think we can update it to 4.15 because we had some tests on OKD 4.15 (#8300) but it should not be within our scope for CVE. |
Action Summary
Won't Fix
|
Pre Ready-For-Testing Checklist
|
All PRs have been merged. This doesn't require effort from @longhorn/qa , any issues introduced should be detected in the daily regression run. Closing. |
What's the task? Please describe
Investigate CVE issues of the Longhorn component images to see if there are outstanding CVE issues that need to be fixed.
Describe the sub-tasks
https://github.com/longhorn/longhorn/blob/v1.7.x/deploy/longhorn-images.txt
Additional context
None
The text was updated successfully, but these errors were encountered: