openshift / machine-config-operator

Apache License 2.0
245 stars 409 forks source link

OCPBUGS-37032: CVE-2024-3727 ose-machine-config-operator-container: containers/image: digest type does not guarantee valid type #4548

Closed djoshy closed 1 month ago

djoshy commented 2 months ago

This bumps github.com/containers/image to v5.29.4 which includes the fix for CVE-2024-3727 vulnerability. More details can be found here.

openshift-ci-robot commented 2 months ago

@djoshy: This pull request references Jira Issue OCPBUGS-37032, which is valid. The bug has been moved to the POST state.

3 validation(s) were run on this bug * bug is open, matching expected state (open) * bug target version (4.18.0) matches configured target version for branch (4.18.0) * bug is in the state New, which is one of the valid states (NEW, ASSIGNED, POST)

Requesting review from QA contact: /cc @sergiordlr

The bug has been updated to refer to the pull request using the external bug tracker.

In response to [this](https://github.com/openshift/machine-config-operator/pull/4548): > > >This bumps github.com/containers/image to v5.29.4 which includes the fix for CVE-2024-3727 vulnerability. More details can be found [here](https://github.com/containers/image/pull/2418#issuecomment-2223604474). > > > Instructions for interacting with me using PR comments are available [here](https://prow.ci.openshift.org/command-help?repo=openshift%2Fmachine-config-operator). If you have questions or suggestions related to my behavior, please file an issue against the [openshift-eng/jira-lifecycle-plugin](https://github.com/openshift-eng/jira-lifecycle-plugin/issues/new) repository.
cheesesashimi commented 2 months ago

/lgtm /approve

cheesesashimi commented 2 months ago

/label acknowledge-critical-fixes-only

cheesesashimi commented 2 months ago

/retest e2e-hypershift

openshift-ci[bot] commented 2 months ago

@cheesesashimi: The /retest command does not accept any targets. The following commands are available to trigger required jobs:

The following commands are available to trigger optional jobs:

Use /test all to run the following jobs that were automatically triggered:

In response to [this](https://github.com/openshift/machine-config-operator/pull/4548#issuecomment-2311021594): >/retest e2e-hypershift Instructions for interacting with me using PR comments are available [here](https://git.k8s.io/community/contributors/guide/pull-requests.md). If you have questions or suggestions related to my behavior, please file an issue against the [kubernetes-sigs/prow](https://github.com/kubernetes-sigs/prow/issues/new?title=Prow%20issue:) repository.
cheesesashimi commented 2 months ago

/test e2e-hypershift

openshift-ci-robot commented 2 months ago

/retest-required

Remaining retests: 0 against base HEAD 005ee68664fa12db7ec159deb984b30421331950 and 2 for PR HEAD bdea4517f8e2f16791aa23ca22b0fab9e80ef999 in total

openshift-ci-robot commented 2 months ago

/retest-required

Remaining retests: 0 against base HEAD 005ee68664fa12db7ec159deb984b30421331950 and 2 for PR HEAD bdea4517f8e2f16791aa23ca22b0fab9e80ef999 in total

openshift-ci-robot commented 2 months ago

/retest-required

Remaining retests: 0 against base HEAD 005ee68664fa12db7ec159deb984b30421331950 and 2 for PR HEAD bdea4517f8e2f16791aa23ca22b0fab9e80ef999 in total

djoshy commented 2 months ago

/test e2e-gcp-op

djoshy commented 2 months ago

/cherrypick release-4.17 release-4.16

openshift-cherrypick-robot commented 2 months ago

@djoshy: once the present PR merges, I will cherry-pick it on top of release-4.17 in a new PR and assign it to you.

In response to [this](https://github.com/openshift/machine-config-operator/pull/4548#issuecomment-2312509152): >/cherrypick release-4.17 release-4.16 Instructions for interacting with me using PR comments are available [here](https://git.k8s.io/community/contributors/guide/pull-requests.md). If you have questions or suggestions related to my behavior, please file an issue against the [kubernetes-sigs/prow](https://github.com/kubernetes-sigs/prow/issues/new?title=Prow%20issue:) repository.
openshift-ci-robot commented 2 months ago

/retest-required

Remaining retests: 0 against base HEAD 005ee68664fa12db7ec159deb984b30421331950 and 2 for PR HEAD bdea4517f8e2f16791aa23ca22b0fab9e80ef999 in total

djoshy commented 2 months ago

/retest

djoshy commented 2 months ago

/retest-required

ptalgulk01 commented 2 months ago

No need of QE verification, the changes does not affect the MCO behaviour. Adding QE approved label

/label qe-approved

openshift-ci-robot commented 2 months ago

@djoshy: This pull request references Jira Issue OCPBUGS-37032, which is valid.

3 validation(s) were run on this bug * bug is open, matching expected state (open) * bug target version (4.18.0) matches configured target version for branch (4.18.0) * bug is in the state POST, which is one of the valid states (NEW, ASSIGNED, POST)

Requesting review from QA contact: /cc @sergiordlr

In response to [this](https://github.com/openshift/machine-config-operator/pull/4548): > > >This bumps github.com/containers/image to v5.29.4 which includes the fix for CVE-2024-3727 vulnerability. More details can be found [here](https://github.com/containers/image/pull/2418#issuecomment-2223604474). > > > Instructions for interacting with me using PR comments are available [here](https://prow.ci.openshift.org/command-help?repo=openshift%2Fmachine-config-operator). If you have questions or suggestions related to my behavior, please file an issue against the [openshift-eng/jira-lifecycle-plugin](https://github.com/openshift-eng/jira-lifecycle-plugin/issues/new) repository.
cheesesashimi commented 1 month ago

/lgtm /approve

openshift-ci[bot] commented 1 month ago

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: cheesesashimi, djoshy

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Needs approval from an approver in each of these files: - ~~[OWNERS](https://github.com/openshift/machine-config-operator/blob/master/OWNERS)~~ [cheesesashimi,djoshy] Approvers can indicate their approval by writing `/approve` in a comment Approvers can cancel approval by writing `/approve cancel` in a comment
openshift-ci-robot commented 1 month ago

/retest-required

Remaining retests: 0 against base HEAD a3d9b1fe6cb9c5140e0a81091f91aef5f8dcc4ba and 2 for PR HEAD 7402f8d862755c4e680b4a397526288eabf37939 in total

openshift-ci-robot commented 1 month ago

/retest-required

Remaining retests: 0 against base HEAD 70d43e63758a3fbb1577387dce9e21a5fe0b2e51 and 2 for PR HEAD 7402f8d862755c4e680b4a397526288eabf37939 in total

djoshy commented 1 month ago

/retest

djoshy commented 1 month ago

/retest

djoshy commented 1 month ago

/retest

openshift-ci[bot] commented 1 month ago

@djoshy: all tests passed!

Full PR test history. Your PR dashboard.

Instructions for interacting with me using PR comments are available [here](https://git.k8s.io/community/contributors/guide/pull-requests.md). If you have questions or suggestions related to my behavior, please file an issue against the [kubernetes-sigs/prow](https://github.com/kubernetes-sigs/prow/issues/new?title=Prow%20issue:) repository. I understand the commands that are listed [here](https://go.k8s.io/bot-commands).
openshift-ci-robot commented 1 month ago

@djoshy: Jira Issue OCPBUGS-37032: All pull requests linked via external trackers have merged:

Jira Issue OCPBUGS-37032 has been moved to the MODIFIED state.

In response to [this](https://github.com/openshift/machine-config-operator/pull/4548): > > >This bumps github.com/containers/image to v5.29.4 which includes the fix for CVE-2024-3727 vulnerability. More details can be found [here](https://github.com/containers/image/pull/2418#issuecomment-2223604474). > > > Instructions for interacting with me using PR comments are available [here](https://prow.ci.openshift.org/command-help?repo=openshift%2Fmachine-config-operator). If you have questions or suggestions related to my behavior, please file an issue against the [openshift-eng/jira-lifecycle-plugin](https://github.com/openshift-eng/jira-lifecycle-plugin/issues/new) repository.
openshift-cherrypick-robot commented 1 month ago

@djoshy: new pull request created: #4564

In response to [this](https://github.com/openshift/machine-config-operator/pull/4548#issuecomment-2312509152): >/cherrypick release-4.17 release-4.16 Instructions for interacting with me using PR comments are available [here](https://git.k8s.io/community/contributors/guide/pull-requests.md). If you have questions or suggestions related to my behavior, please file an issue against the [kubernetes-sigs/prow](https://github.com/kubernetes-sigs/prow/issues/new?title=Prow%20issue:) repository.
openshift-bot commented 1 month ago

[ART PR BUILD NOTIFIER]

Distgit: ose-machine-config-operator This PR has been included in build ose-machine-config-operator-container-v4.18.0-202409060444.p0.g1264949.assembly.stream.el9. All builds following this will include this PR.