release icon indicating copy to clipboard operation
release copied to clipboard

Patching for base images

Open sozercan opened this issue 4 years ago • 17 comments
trafficstars

What would you like to be added:

Are there any plans to automatically patch actionable CVEs in base images, such as debian-base, and push new versions? Is this a manual process today?

Why is this needed:

It would be ideal if base image versions are automated when an actionable CVE is found so individual projects don't have to maintain OS level patching.

sozercan avatar Jan 07 '21 22:01 sozercan

I'll start thinking about this. If anyone wants to sync with me on this issue let me know. /help

puerco avatar Feb 03 '21 20:02 puerco

@puerco: This request has been marked as needing help from a contributor.

Please ensure the request meets the requirements listed here.

If this request no longer meets these requirements, the label can be removed by commenting with the /remove-help command.

In response to this:

I'll start thinking about this. If anyone wants to sync with me on this issue let me know. /help

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository.

k8s-ci-robot avatar Feb 03 '21 20:02 k8s-ci-robot

Interesting topic. What would be the source of information for available CVEs?

saschagrunert avatar Feb 04 '21 08:02 saschagrunert

I'll start thinking about this. If anyone wants to sync with me on this issue let me know.

I would like to work together on it.

nasirhm avatar Feb 08 '21 17:02 nasirhm

@puerco I could help assist you with this. Let me know how : ) and would love to help

sladyn98 avatar Feb 17 '21 18:02 sladyn98

@puerco has there been any progress on this? I am leading a new sub-group sig-security-tooling and would like to give this more visibility in our upcoming meeting so we can collaborate on this. Let me know what you think :)

/sig security

PushkarJ avatar Jun 10 '21 18:06 PushkarJ

The Kubernetes project currently lacks enough contributors to adequately respond to all issues and PRs.

This bot triages issues and PRs according to the following rules:

  • After 90d of inactivity, lifecycle/stale is applied
  • After 30d of inactivity since lifecycle/stale was applied, lifecycle/rotten is applied
  • After 30d of inactivity since lifecycle/rotten was applied, the issue is closed

You can:

  • Mark this issue or PR as fresh with /remove-lifecycle stale
  • Mark this issue or PR as rotten with /lifecycle rotten
  • Close this issue or PR with /close
  • Offer to help out with Issue Triage

Please send feedback to sig-contributor-experience at kubernetes/community.

/lifecycle stale

k8s-triage-robot avatar Sep 08 '21 18:09 k8s-triage-robot

The Kubernetes project currently lacks enough contributors to adequately respond to all issues and PRs.

This bot triages issues and PRs according to the following rules:

  • After 90d of inactivity, lifecycle/stale is applied
  • After 30d of inactivity since lifecycle/stale was applied, lifecycle/rotten is applied
  • After 30d of inactivity since lifecycle/rotten was applied, the issue is closed

You can:

  • Mark this issue or PR as fresh with /remove-lifecycle stale
  • Mark this issue or PR as rotten with /lifecycle rotten
  • Close this issue or PR with /close
  • Offer to help out with Issue Triage

Please send feedback to sig-contributor-experience at kubernetes/community.

/lifecycle stale

k8s-triage-robot avatar Dec 07 '21 20:12 k8s-triage-robot

/remove-lifecycle stale

sozercan avatar Dec 09 '21 22:12 sozercan

The Kubernetes project currently lacks enough contributors to adequately respond to all issues and PRs.

This bot triages issues and PRs according to the following rules:

  • After 90d of inactivity, lifecycle/stale is applied
  • After 30d of inactivity since lifecycle/stale was applied, lifecycle/rotten is applied
  • After 30d of inactivity since lifecycle/rotten was applied, the issue is closed

You can:

  • Mark this issue or PR as fresh with /remove-lifecycle stale
  • Mark this issue or PR as rotten with /lifecycle rotten
  • Close this issue or PR with /close
  • Offer to help out with Issue Triage

Please send feedback to sig-contributor-experience at kubernetes/community.

/lifecycle stale

k8s-triage-robot avatar Mar 09 '22 22:03 k8s-triage-robot

/remove-lifecycle stale

sozercan avatar Mar 09 '22 22:03 sozercan

The Kubernetes project currently lacks enough contributors to adequately respond to all issues and PRs.

This bot triages issues and PRs according to the following rules:

  • After 90d of inactivity, lifecycle/stale is applied
  • After 30d of inactivity since lifecycle/stale was applied, lifecycle/rotten is applied
  • After 30d of inactivity since lifecycle/rotten was applied, the issue is closed

You can:

  • Mark this issue or PR as fresh with /remove-lifecycle stale
  • Mark this issue or PR as rotten with /lifecycle rotten
  • Close this issue or PR with /close
  • Offer to help out with Issue Triage

Please send feedback to sig-contributor-experience at kubernetes/community.

/lifecycle stale

k8s-triage-robot avatar Jun 07 '22 23:06 k8s-triage-robot

/remove-lifecycle stale

puerco avatar Jun 07 '22 23:06 puerco

The Kubernetes project currently lacks enough contributors to adequately respond to all issues and PRs.

This bot triages issues and PRs according to the following rules:

  • After 90d of inactivity, lifecycle/stale is applied
  • After 30d of inactivity since lifecycle/stale was applied, lifecycle/rotten is applied
  • After 30d of inactivity since lifecycle/rotten was applied, the issue is closed

You can:

  • Mark this issue or PR as fresh with /remove-lifecycle stale
  • Mark this issue or PR as rotten with /lifecycle rotten
  • Close this issue or PR with /close
  • Offer to help out with Issue Triage

Please send feedback to sig-contributor-experience at kubernetes/community.

/lifecycle stale

k8s-triage-robot avatar Sep 05 '22 23:09 k8s-triage-robot

/remove-lifecycle stale

sozercan avatar Sep 07 '22 21:09 sozercan

The Kubernetes project currently lacks enough contributors to adequately respond to all PRs.

This bot triages PRs according to the following rules:

  • After 90d of inactivity, lifecycle/stale is applied
  • After 30d of inactivity since lifecycle/stale was applied, lifecycle/rotten is applied
  • After 30d of inactivity since lifecycle/rotten was applied, the PR is closed

You can:

  • Mark this PR as fresh with /remove-lifecycle stale
  • Close this PR with /close
  • Offer to help out with Issue Triage

Please send feedback to sig-contributor-experience at kubernetes/community.

/lifecycle stale

k8s-triage-robot avatar Feb 08 '23 03:02 k8s-triage-robot

/remove-lifecycle stale

sozercan avatar Mar 21 '23 18:03 sozercan