Skip to content

Commit e23ea1f

Browse files
fix(kubectl): cve (#528)
1 parent f56f492 commit e23ea1f

File tree

3 files changed

+8
-10
lines changed

3 files changed

+8
-10
lines changed

charts/cf-runtime/Chart.yaml

Lines changed: 2 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
apiVersion: v2
22
description: A Helm chart for Codefresh Runner
33
name: cf-runtime
4-
version: 7.1.4
4+
version: 7.1.5
55
keywords:
66
- codefresh
77
- runner
@@ -17,10 +17,8 @@ annotations:
1717
artifacthub.io/containsSecurityUpdates: "true"
1818
# Supported kinds: `added`, `changed`, `deprecated`, `removed`, `fixed`, `security`:
1919
artifacthub.io/changes: |
20-
- kind: fixed
21-
description: "Fixed support for `docker` driver in `build` step"
2220
- kind: security
23-
description: "CVE fixed in `dind` image"
21+
description: "Replace codefresh/codefresh-shell image with codefresh/kubectl"
2422
dependencies:
2523
- name: cf-common
2624
repository: oci://quay.io/codefresh/charts

charts/cf-runtime/README.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
## Codefresh Runner
22

3-
![Version: 7.1.4](https://img.shields.io/badge/Version-7.1.4-informational?style=flat-square)
3+
![Version: 7.1.5](https://img.shields.io/badge/Version-7.1.5-informational?style=flat-square)
44

55
Helm chart for deploying [Codefresh Runner](https://codefresh.io/docs/docs/installation/codefresh-runner/) to Kubernetes.
66

@@ -1170,7 +1170,7 @@ Go to [https://<YOUR_ONPREM_DOMAIN_HERE>/admin/runtime-environments/system](http
11701170
| runner.serviceAccount.annotations | object | `{}` | Additional service account annotations |
11711171
| runner.serviceAccount.create | bool | `true` | Create service account |
11721172
| runner.serviceAccount.name | string | `""` | Override service account name |
1173-
| runner.sidecar | object | `{"enabled":false,"env":{"RECONCILE_INTERVAL":300},"image":{"digest":"sha256:e60e9e57979b0f02dc850b25b4808e72dda90c6a50eb40deadce0590f8ad1845","registry":"quay.io","repository":"codefresh/codefresh-shell","tag":"0.0.21"},"resources":{}}` | Sidecar container Reconciles runtime spec from Codefresh API for drift detection |
1173+
| runner.sidecar | object | `{"enabled":false,"env":{"RECONCILE_INTERVAL":300},"image":{"digest":"sha256:a30a8810dde249d0198f67792ed9696363f15c8cecbac955ee9bd267b5454ee7","registry":"quay.io","repository":"codefresh/kubectl","tag":"1.31.2"},"resources":{}}` | Sidecar container Reconciles runtime spec from Codefresh API for drift detection |
11741174
| runner.tolerations | list | `[]` | Set tolerations |
11751175
| runner.updateStrategy | object | `{"type":"RollingUpdate"}` | Upgrade strategy |
11761176
| runtime | object | See below | Set runtime parameters |

charts/cf-runtime/values.yaml

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -94,9 +94,9 @@ runner:
9494
enabled: false
9595
image:
9696
registry: quay.io
97-
repository: codefresh/codefresh-shell
98-
tag: 0.0.21
99-
digest: sha256:e60e9e57979b0f02dc850b25b4808e72dda90c6a50eb40deadce0590f8ad1845
97+
repository: codefresh/kubectl
98+
tag: 1.31.2
99+
digest: sha256:a30a8810dde249d0198f67792ed9696363f15c8cecbac955ee9bd267b5454ee7
100100
env:
101101
RECONCILE_INTERVAL: 300
102102
resources: {}
@@ -621,7 +621,7 @@ runtime:
621621
registry: quay.io
622622
repository: codefresh/kubectl
623623
tag: 1.31.2
624-
digest: sha256:ee724ff89b68f06c36b44f01b4feac3f2cfde5aa7ae9bad11577d82a9fcd48ab
624+
digest: sha256:a30a8810dde249d0198f67792ed9696363f15c8cecbac955ee9bd267b5454ee7
625625
rbac:
626626
enabled: true
627627
annotations: {}

0 commit comments

Comments
 (0)