OCPBUGS-42156: Switch to github.com/docker/distribution/reference to Mitigate CVE-2024-3727
The library github.com/containers/image/v5 has a vulnerability that has as of yet been unresolved.
Thankfully, it is possible to change the part of the library that we use
We can change github.com/containers/image/v5/docker/reference for github.com/docker/distribution/reference
In the case of assisted-installer, we achieve this by changing the dependency to the latest assisted-installer
@paul-maidment: This pull request references Jira Issue OCPBUGS-42156, which is invalid:
- expected dependent Jira Issue OCPBUGS-42077 to be in one of the following states: MODIFIED, ON_QA, VERIFIED, but it is POST instead
Comment /jira refresh to re-evaluate validity if changes to the Jira bug are made, or edit the title of this pull request to link to a different bug.
The bug has been updated to refer to the pull request using the external bug tracker.
In response to this:
…Mitigate CVE-2024-3727
The library github.com/containers/image/v5 has a vulnerability that has as of yet been unresolved.
Thankfully, it is possible to change the part of the library that we use
We can change github.com/containers/image/v5/docker/reference for github.com/docker/distribution/reference
In the case of assisted-installer, we achieve this by changing the dependency to the latest assisted-installer
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.
[APPROVALNOTIFIER] This PR is APPROVED
This pull-request has been approved by: adriengentil, paul-maidment
The full list of commands accepted by this bot can be found here.
The pull request process is described here
- ~~OWNERS~~ [adriengentil,paul-maidment]
Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment
@paul-maidment: all tests passed!
Full PR test history. Your PR dashboard.
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.
/label backport-risk-assessed /label cherry-pick-approved
@rccrdpccl: Can not set label backport-risk-assessed: Must be member in one of these teams: [openshift-patch-managers openshift-staff-engineers openshift-release-oversight]
In response to this:
/label backport-risk-assessed /label cherry-pick-approved
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.
@rccrdpccl: Can not set label cherry-pick-approved: Must be member in one of these teams: [openshift-patch-managers openshift-staff-engineers openshift-release-oversight]
In response to this:
/label backport-risk-assessed /label cherry-pick-approved
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.
@paul-maidment: This pull request references Jira Issue OCPBUGS-42156, which is invalid:
- expected dependent Jira Issue OCPBUGS-42186 to be in one of the following states: MODIFIED, ON_QA, VERIFIED, but it is New instead
- expected dependent Jira Issue OCPBUGS-42077 to be in one of the following states: MODIFIED, ON_QA, VERIFIED, but it is POST instead
Comment /jira refresh to re-evaluate validity if changes to the Jira bug are made, or edit the title of this pull request to link to a different bug.
The bug has been updated to refer to the pull request using the external bug tracker.
In response to this:
The library github.com/containers/image/v5 has a vulnerability that has as of yet been unresolved.
Thankfully, it is possible to change the part of the library that we use
We can change github.com/containers/image/v5/docker/reference for github.com/docker/distribution/reference
In the case of assisted-installer, we achieve this by changing the dependency to the latest assisted-installer
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.
/jira refresh
@paul-maidment: This pull request references Jira Issue OCPBUGS-42156, which is invalid:
- expected dependent Jira Issue OCPBUGS-42186 to be in one of the following states: MODIFIED, ON_QA, VERIFIED, but it is New instead
- expected dependent Jira Issue OCPBUGS-42077 to be in one of the following states: MODIFIED, ON_QA, VERIFIED, but it is POST instead
Comment /jira refresh to re-evaluate validity if changes to the Jira bug are made, or edit the title of this pull request to link to a different bug.
In response to this:
/jira refresh
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.
/jira refresh
@paul-maidment: This pull request references Jira Issue OCPBUGS-42156, which is invalid:
- expected dependent Jira Issue OCPBUGS-42075 to target a version in 4.18.0, but it targets "4.17.0" instead
Comment /jira refresh to re-evaluate validity if changes to the Jira bug are made, or edit the title of this pull request to link to a different bug.
In response to this:
/jira refresh
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.
/jira refresh
@paul-maidment: This pull request references Jira Issue OCPBUGS-42156, which is valid. The bug has been moved to the POST state.
7 validation(s) were run on this bug
- bug is open, matching expected state (open)
- bug target version (4.17.0) matches configured target version for branch (4.17.0)
- bug is in the state New, which is one of the valid states (NEW, ASSIGNED, POST)
- release note text is set and does not match the template
- dependent bug Jira Issue OCPBUGS-36577 is in the state ON_QA, which is one of the valid states (MODIFIED, ON_QA, VERIFIED)
- dependent Jira Issue OCPBUGS-36577 targets the "4.18.0" version, which is one of the valid target versions: 4.18.0
- bug has dependents
Requesting review from QA contact: /cc @mhanss
In response to this:
/jira refresh
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.
@zaneb @andfasano can you help with the required label? thanks
@paul-maidment: Jira Issue OCPBUGS-42156: All pull requests linked via external trackers have merged:
Jira Issue OCPBUGS-42156 has been moved to the MODIFIED state.
In response to this:
The library github.com/containers/image/v5 has a vulnerability that has as of yet been unresolved.
Thankfully, it is possible to change the part of the library that we use
We can change github.com/containers/image/v5/docker/reference for github.com/docker/distribution/reference
In the case of assisted-installer, we achieve this by changing the dependency to the latest assisted-installer
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.
[ART PR BUILD NOTIFIER]
Distgit: ose-agent-installer-orchestrator This PR has been included in build ose-agent-installer-orchestrator-container-v4.17.0-202410022234.p0.gfbc55c6.assembly.stream.el9. All builds following this will include this PR.
[ART PR BUILD NOTIFIER]
Distgit: ose-agent-installer-csr-approver This PR has been included in build ose-agent-installer-csr-approver-container-v4.17.0-202410022234.p0.gfbc55c6.assembly.stream.el9. All builds following this will include this PR.