Skip to content

Fix Critical CVEs on Epoxy Kolla container images #1701

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 6 commits into from
Jun 13, 2025

Conversation

seunghun1ee
Copy link
Member

CVE-2024-45337 of InfluxDB was allowed as there is no upstream fix available.

@seunghun1ee seunghun1ee self-assigned this Jun 11, 2025
@seunghun1ee seunghun1ee requested a review from a team as a code owner June 11, 2025 13:50
@product-auto-label product-auto-label bot added size: m kolla workflows Workflow files have been modified labels Jun 11, 2025
@priteau
Copy link
Member

priteau commented Jun 11, 2025

Is this using Rocky Linux 9.6?

@seunghun1ee
Copy link
Member Author

Is this using Rocky Linux 9.6?

Kolla images for rocky should be built on top of 9.5 as stackhpc_pulp_repo_rocky_9_minor_version is set to 5.

@priteau
Copy link
Member

priteau commented Jun 11, 2025

Is this using Rocky Linux 9.6?

Kolla images for rocky should be built on top of 9.5 as stackhpc_pulp_repo_rocky_9_minor_version is set to 5.

We can merge this if it works, but let's rebuild with 9.6 separately. We don't want to ship an already outdated distribution.

@Alex-Welsh
Copy link
Member

CI fix: #1704

@seunghun1ee seunghun1ee merged commit 09f7a38 into stackhpc/2025.1 Jun 13, 2025
32 of 36 checks passed
@seunghun1ee seunghun1ee deleted the epoxy-cve-fix2 branch June 13, 2025 13:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
kolla size: m workflows Workflow files have been modified
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants