Skip to content

Release 1.11#2876

Closed
TomSweeneyRedHat wants to merge 32 commits into
mainfrom
release-1.11
Closed

Release 1.11#2876
TomSweeneyRedHat wants to merge 32 commits into
mainfrom
release-1.11

Conversation

@TomSweeneyRedHat

Copy link
Copy Markdown
Contributor

No description provided.

mtrmac and others added 30 commits February 9, 2023 21:12
... to include an unexpected EOF workaround.

Signed-off-by: Miloslav Trmač <mitr@redhat.com>
[release-1.11] Update to c/image 5.24.1
As the title says.  To ready for RHEL 8.8/9.2

[NO NEW TESTS NEEDED]

Signed-off-by: tomsweeneyredhat <tsweeney@redhat.com>
As the title says

[NO NEW TESTS NEEDEDED]

Signed-off-by: tomsweeneyredhat <tsweeney@redhat.com>
Resolves: CVE-2022-41723
Ref: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2022-41723

Signed-off-by: Lokesh Mandvekar <lsm5@fedoraproject.org>
[release-1.11] bump golang.org/x/net to v0.7.0
Updates golang.org/x/net to v0.7.0 to resolve CVE-2022-41723.

Signed-off-by: Miloslav Trmač <mitr@redhat.com>
Signed-off-by: Miloslav Trmač <mitr@redhat.com>
This branch will never receive any security-backports when the
associated RHEL release reaches EOL.  Add a condition to force CI to
break with a helpful message, after this RHEL EOL date.

Signed-off-by: Chris Evich <cevich@redhat.com>
[release-1.11] Cirrus: Add CI self-destruct condition on EOL date
... because the tests are assuming a v2s2 image, but
as of Fedora 39, the image uses the OCI format.

Signed-off-by: Miloslav Trmač <mitr@redhat.com>
Bump github.com/go-jose/go-jose to v3.0.0 and
github.com/containers/ocicrypt to v1.1.10

Addresses: CVE-2024-28180
https://issues.redhat.com/browse/OCPBUGS-30789
https://issues.redhat.com/browse/OCPBUGS-30790
https://issues.redhat.com/browse/OCPBUGS-30791

Signed-off-by: tomsweeneyredhat <tsweeney@redhat.com>
... per https://kubernetes.io/blog/2023/02/06/k8s-gcr-io-freeze-announcement/ .

We are seeing intermittent failures (sufficient to reliably cause a test suite failure)
pulling from k8s.gcr.io, let's see if using the newer one improves things.

Signed-off-by: Miloslav Trmač <mitr@redhat.com>
[release-1.11] Refer to registry.k8s.io instead of k8s.gcr.io
Addresses CVE-2024-3727 by bumping c/common to v0.51.4 and c/image
to v5.24.3

Fixes: https://issues.redhat.com/browse/OCPBUGS-37020
https://issues.redhat.com/browse/OCPBUGS-37022
https://issues.redhat.com/browse/OCPBUGS-37023

Signed-off-by: tomsweeneyredhat <tsweeney@redhat.com>
Previously, internal CI gating tests sometimes fail because the required
registry container image only supports x86_64.  Update to the `2.8.2`
image tag with support for all primary architectures.

Signed-off-by: Chris Evich <cevich@redhat.com>
[release-1.11] Support CI testing on non-x86_64
Unfortunately on a number of occasions, Skopeo has been released
officially with a `-dev` suffix in the version number.  Assist in
catching this mistake at release time by the addition of a simple
conditional test.  Note that it must be positively enabled by a
magic env. var. before executing the system tests.

Original PR: #2631

Signed-off-by: Chris Evich <cevich@redhat.com>
[release-1.11] Add conditional release-checking system test
This branch is utilized for RHEL releases and therefore should never
ever represent a `-dev` development release.  Bump the version
number to account for the change.

Resolves: RHEL-97092 RHEL-97090

Signed-off-by: Chris Evich <cevich@redhat.com>
[release-1.11] Bump to release version 1.11.3
As the title says!

Signed-off-by: tomsweeneyredhat <tsweeney@redhat.com>
The lastest Go Jose is calling functions first introduced in Go 1.20.
Bumping the CI to Fedora 1.39 where Go 1.20 first appeared in Fedora.

Signed-off-by: Tom Sweeney <tsweeney@redhat.com>
Bump Skopeo to v1.11.5

Signed-off-by: Tom Sweeney <tsweeney@redhat.com>
….11-cve-2026-34986

[release-1.11] Bump Go Jose to v3.0.5, CVE-2026-34986, Skopeo to v1.11.5
@TomSweeneyRedHat

Copy link
Copy Markdown
Contributor Author

Killing. Somehow Git thinks a PR came through from me and it did not.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants