assisted-installer icon indicating copy to clipboard operation
assisted-installer copied to clipboard

OCPBUGS-42156: Switch to github.com/docker/distribution/reference to Mitigate CVE-2024-3727

Open paul-maidment opened this issue 1 year ago • 14 comments

The library github.com/containers/image/v5 has a vulnerability that has as of yet been unresolved.

Thankfully, it is possible to change the part of the library that we use

We can change github.com/containers/image/v5/docker/reference for github.com/docker/distribution/reference

In the case of assisted-installer, we achieve this by changing the dependency to the latest assisted-installer

paul-maidment avatar Sep 18 '24 14:09 paul-maidment

@paul-maidment: This pull request references Jira Issue OCPBUGS-42156, which is invalid:

  • expected dependent Jira Issue OCPBUGS-42077 to be in one of the following states: MODIFIED, ON_QA, VERIFIED, but it is POST instead

Comment /jira refresh to re-evaluate validity if changes to the Jira bug are made, or edit the title of this pull request to link to a different bug.

The bug has been updated to refer to the pull request using the external bug tracker.

In response to this:

…Mitigate CVE-2024-3727

The library github.com/containers/image/v5 has a vulnerability that has as of yet been unresolved.

Thankfully, it is possible to change the part of the library that we use

We can change github.com/containers/image/v5/docker/reference for github.com/docker/distribution/reference

In the case of assisted-installer, we achieve this by changing the dependency to the latest assisted-installer

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

openshift-ci-robot avatar Sep 18 '24 14:09 openshift-ci-robot

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: adriengentil, paul-maidment

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Needs approval from an approver in each of these files:
  • ~~OWNERS~~ [adriengentil,paul-maidment]

Approvers can indicate their approval by writing /approve in a comment Approvers can cancel approval by writing /approve cancel in a comment

openshift-ci[bot] avatar Sep 18 '24 14:09 openshift-ci[bot]

@paul-maidment: all tests passed!

Full PR test history. Your PR dashboard.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

openshift-ci[bot] avatar Sep 18 '24 15:09 openshift-ci[bot]

/label backport-risk-assessed /label cherry-pick-approved

rccrdpccl avatar Sep 19 '24 07:09 rccrdpccl

@rccrdpccl: Can not set label backport-risk-assessed: Must be member in one of these teams: [openshift-patch-managers openshift-staff-engineers openshift-release-oversight]

In response to this:

/label backport-risk-assessed /label cherry-pick-approved

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

openshift-ci[bot] avatar Sep 19 '24 07:09 openshift-ci[bot]

@rccrdpccl: Can not set label cherry-pick-approved: Must be member in one of these teams: [openshift-patch-managers openshift-staff-engineers openshift-release-oversight]

In response to this:

/label backport-risk-assessed /label cherry-pick-approved

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

openshift-ci[bot] avatar Sep 19 '24 07:09 openshift-ci[bot]

@paul-maidment: This pull request references Jira Issue OCPBUGS-42156, which is invalid:

  • expected dependent Jira Issue OCPBUGS-42186 to be in one of the following states: MODIFIED, ON_QA, VERIFIED, but it is New instead
  • expected dependent Jira Issue OCPBUGS-42077 to be in one of the following states: MODIFIED, ON_QA, VERIFIED, but it is POST instead

Comment /jira refresh to re-evaluate validity if changes to the Jira bug are made, or edit the title of this pull request to link to a different bug.

The bug has been updated to refer to the pull request using the external bug tracker.

In response to this:

The library github.com/containers/image/v5 has a vulnerability that has as of yet been unresolved.

Thankfully, it is possible to change the part of the library that we use

We can change github.com/containers/image/v5/docker/reference for github.com/docker/distribution/reference

In the case of assisted-installer, we achieve this by changing the dependency to the latest assisted-installer

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

openshift-ci-robot avatar Sep 19 '24 07:09 openshift-ci-robot

/jira refresh

paul-maidment avatar Sep 19 '24 07:09 paul-maidment

@paul-maidment: This pull request references Jira Issue OCPBUGS-42156, which is invalid:

  • expected dependent Jira Issue OCPBUGS-42186 to be in one of the following states: MODIFIED, ON_QA, VERIFIED, but it is New instead
  • expected dependent Jira Issue OCPBUGS-42077 to be in one of the following states: MODIFIED, ON_QA, VERIFIED, but it is POST instead

Comment /jira refresh to re-evaluate validity if changes to the Jira bug are made, or edit the title of this pull request to link to a different bug.

In response to this:

/jira refresh

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

openshift-ci-robot avatar Sep 19 '24 07:09 openshift-ci-robot

/jira refresh

paul-maidment avatar Sep 19 '24 07:09 paul-maidment

@paul-maidment: This pull request references Jira Issue OCPBUGS-42156, which is invalid:

Comment /jira refresh to re-evaluate validity if changes to the Jira bug are made, or edit the title of this pull request to link to a different bug.

In response to this:

/jira refresh

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

openshift-ci-robot avatar Sep 19 '24 07:09 openshift-ci-robot

/jira refresh

paul-maidment avatar Sep 19 '24 07:09 paul-maidment

@paul-maidment: This pull request references Jira Issue OCPBUGS-42156, which is valid. The bug has been moved to the POST state.

7 validation(s) were run on this bug
  • bug is open, matching expected state (open)
  • bug target version (4.17.0) matches configured target version for branch (4.17.0)
  • bug is in the state New, which is one of the valid states (NEW, ASSIGNED, POST)
  • release note text is set and does not match the template
  • dependent bug Jira Issue OCPBUGS-36577 is in the state ON_QA, which is one of the valid states (MODIFIED, ON_QA, VERIFIED)
  • dependent Jira Issue OCPBUGS-36577 targets the "4.18.0" version, which is one of the valid target versions: 4.18.0
  • bug has dependents

Requesting review from QA contact: /cc @mhanss

In response to this:

/jira refresh

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

openshift-ci-robot avatar Sep 19 '24 07:09 openshift-ci-robot

@zaneb @andfasano can you help with the required label? thanks

gamli75 avatar Sep 19 '24 17:09 gamli75

@paul-maidment: Jira Issue OCPBUGS-42156: All pull requests linked via external trackers have merged:

Jira Issue OCPBUGS-42156 has been moved to the MODIFIED state.

In response to this:

The library github.com/containers/image/v5 has a vulnerability that has as of yet been unresolved.

Thankfully, it is possible to change the part of the library that we use

We can change github.com/containers/image/v5/docker/reference for github.com/docker/distribution/reference

In the case of assisted-installer, we achieve this by changing the dependency to the latest assisted-installer

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

openshift-ci-robot avatar Oct 02 '24 19:10 openshift-ci-robot

[ART PR BUILD NOTIFIER]

Distgit: ose-agent-installer-orchestrator This PR has been included in build ose-agent-installer-orchestrator-container-v4.17.0-202410022234.p0.gfbc55c6.assembly.stream.el9. All builds following this will include this PR.

openshift-bot avatar Oct 02 '24 23:10 openshift-bot

[ART PR BUILD NOTIFIER]

Distgit: ose-agent-installer-csr-approver This PR has been included in build ose-agent-installer-csr-approver-container-v4.17.0-202410022234.p0.gfbc55c6.assembly.stream.el9. All builds following this will include this PR.

openshift-bot avatar Oct 02 '24 23:10 openshift-bot