cloudfoundry / cf-mysql-release

Cloud Foundry MySQL Release
Apache License 2.0
58 stars 106 forks source link

security: mariadb bump to 10.1.37 #218

Closed thelangley closed 5 years ago

thelangley commented 6 years ago

Upgrade mariadb version to 10.1.37 to fix vulnerabilities

Vulnerabilities include:

See https://mariadb.com/kb/en/library/mariadb-10137-release-notes/ for more information

Proposed solution/feature

Update references in the release for mariadb/mariadb-10.1.36.tar.gz to mariadb/mariadb-10.1.37.tar.gz

cf-gitbot commented 6 years ago

We have created an issue in Pivotal Tracker to manage this:

https://www.pivotaltracker.com/story/show/162121024

The labels on this github issue will be updated when the story is started.

menicosia commented 5 years ago

Hi @thelangley,

Sorry for the delay on this. This will ultimately be covered in story #161737247. Recently MariaDB made a change which broke our pipelines. We've filed a MariaDB bug: MDEV-18059. In the meanwhile, we've settled on a workaround, which will be covered in story #163045333.

As soon as we've gotten to that story, we'll be unblocked from upgrading to MariaDB 10.1.37, and will be able to close this issue.

Thank you for pinging us!

-- Marco Nicosia Product Manager Pivotal Software, Inc

thelangley commented 5 years ago

The last release bumped to 10.1.38 so this one is sorted. Thanks everyone :)