loki icon indicating copy to clipboard operation
loki copied to clipboard

chore: Update nginx-unprivileged

Open jlm0x017 opened this issue 1 year ago • 3 comments

What this PR does / why we need it:

1.27-alpine is the latest at the time of change - https://hub.docker.com/r/nginxinc/nginx-unprivileged/tags

the 1.24-alpine image is reportedly vulnerable to the following CVE: CVE-2023-44487 CVE-2024-2398 CVE-2024-2466 CVE-2024-34459 CVE-2024-6197

Which issue(s) this PR fixes: n/a

Special notes for your reviewer: just added https://github.com/grafana/loki/pull/13979 that also bumps the chart version. they share the same chart version as I have no idea which will be approved first. If approved and committed the linked PR will need version bumped.

Checklist

  • [x] Reviewed the CONTRIBUTING.md guide (required)
  • [ ] Documentation added
  • [ ] Tests updated
  • [x] Title matches the required conventional commits format, see here
    • Note that Promtail is considered to be feature complete, and future development for logs collection will be in Grafana Alloy. As such, feat PRs are unlikely to be accepted unless a case can be made for the feature actually being a bug fix to existing behavior.
  • [ ] Changes that require user attention or interaction to upgrade are documented in docs/sources/setup/upgrade/_index.md
  • [x] For Helm chart changes bump the Helm chart version in production/helm/loki/Chart.yaml and update production/helm/loki/CHANGELOG.md and production/helm/loki/README.md. Example PR
  • [ ] If the change is deprecating or removing a configuration option, update the deprecated-config.yaml and deleted-config.yaml files respectively in the tools/deprecated-config-checker directory. Example PR

jlm0x017 avatar Aug 27 '24 17:08 jlm0x017

CLA assistant check
All committers have signed the CLA.

CLAassistant avatar Aug 27 '24 17:08 CLAassistant

@jlm0x017 once you rebase this, I'll kick off the builds and get it merged. It may be Thursday when I get to it, but I will do my best to get to it tomorrow.

paul1r avatar Aug 28 '24 00:08 paul1r

@paul1r updated; thanks!

jlm0x017 avatar Aug 28 '24 22:08 jlm0x017