Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[release-1.33] Bump c/storage to v1.51.2, fixes CVE-2024-9676 #5799

Conversation

TomSweeneyRedHat
Copy link
Member

Bump c/storage to v151.2, which gets the fix for CVE-2024-9676
Then bump Buildah to v1.33.11 to vendor elsewhere.

Fixes: https://issues.redhat.com/browse/RHEL-61853, https://issues.redhat.com/browse/RHEL-61860

What type of PR is this?

/kind api-change
/kind bug
/kind cleanup
/kind deprecation
/kind design
/kind documentation
/kind failing-test
/kind feature
/kind flake
/kind other

What this PR does / why we need it:

How to verify it

Which issue(s) this PR fixes:

Special notes for your reviewer:

Does this PR introduce a user-facing change?

None

As the title says, bumping to Buildah v1.33.11
This will contain fixes for CVE-2024-9676

[NO NEW TESTS NEEDED]

Signed-off-by: tomsweeneyredhat <[email protected]>
Copy link
Contributor

openshift-ci bot commented Oct 25, 2024

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: TomSweeneyRedHat

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

Copy link

Ephemeral COPR build failed. @containers/packit-build please check.

@nalind
Copy link
Member

nalind commented Oct 25, 2024

/lgtm

@openshift-ci openshift-ci bot added the lgtm label Oct 25, 2024
@openshift-merge-bot openshift-merge-bot bot merged commit fe85f0d into containers:release-1.33 Oct 25, 2024
30 of 36 checks passed
@stale-locking-app stale-locking-app bot locked as resolved and limited conversation to collaborators Jan 24, 2025
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants