Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade to Docker 25.x #6072

Closed
hannes-ucsc opened this issue Mar 20, 2024 · 2 comments
Closed

Upgrade to Docker 25.x #6072

hannes-ucsc opened this issue Mar 20, 2024 · 2 comments
Assignees
Labels
+ [priority] High demo [process] To be demonstrated at the end of the sprint demoed [process] Successfully demonstrated to team enh [type] New feature or request infra [subject] Project infrastructure like CI/CD, build and deployment scripts orange [process] Done by the Azul team security

Comments

@hannes-ucsc
Copy link
Member

CVE-2024-23653
CVE-2024-23652

Our options are to upgrade to Docker 25.x or to wait until the fix is backported. There is a backport PR but it's been dormant for a month. Seem like we can't wait any longer.

Originally posted by @hannes-ucsc in #6007 (comment)

@github-actions github-actions bot added the orange [process] Done by the Azul team label Mar 20, 2024
@achave11-ucsc achave11-ucsc added enh [type] New feature or request infra [subject] Project infrastructure like CI/CD, build and deployment scripts security + [priority] High labels Mar 20, 2024
@achave11-ucsc achave11-ucsc self-assigned this Mar 20, 2024
@achave11-ucsc
Copy link
Member

achave11-ucsc commented Mar 21, 2024

Upgrade was successfully tested for compatibility in the Upgrades PR pipeline in sandbox.

@hannes-ucsc
Copy link
Member Author

For demo, show that inspector reports the findings for the two critical CVEs as fixed.

@hannes-ucsc hannes-ucsc added the demo [process] To be demonstrated at the end of the sprint label Mar 22, 2024
achave11-ucsc added a commit that referenced this issue Mar 26, 2024
achave11-ucsc added a commit that referenced this issue Mar 26, 2024
achave11-ucsc added a commit that referenced this issue Mar 26, 2024
@achave11-ucsc achave11-ucsc added the demoed [process] Successfully demonstrated to team label Apr 23, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
+ [priority] High demo [process] To be demonstrated at the end of the sprint demoed [process] Successfully demonstrated to team enh [type] New feature or request infra [subject] Project infrastructure like CI/CD, build and deployment scripts orange [process] Done by the Azul team security
Projects
None yet
Development

No branches or pull requests

2 participants