puppetlabs / puppet-runtime

runtime dependencies for Vanagon projects
Apache License 2.0
5 stars 88 forks source link

(PA-6507)(PA-6736) Gem install rexml to 3.3.2 for CVE-2024-35176 and CVE-2024-… #878

Closed shubhamshinde360 closed 1 month ago

shubhamshinde360 commented 1 month ago

…39908

shubhamshinde360 commented 1 month ago

Tested all platforms applicable for the impacted projects:

pe-bolt-server-runtime-main: https://jenkins-platform.delivery.puppetlabs.net/view/vanagon-generic-builder/job/platform_vanagon-generic-builder_vanagon-packaging_generic-builder/3084/

agent-runtime-7.x: https://jenkins-platform.delivery.puppetlabs.net/view/vanagon-generic-builder/job/platform_vanagon-generic-builder_vanagon-packaging_generic-builder/3087/

agent-runtime-main: https://jenkins-platform.delivery.puppetlabs.net/view/vanagon-generic-builder/job/platform_vanagon-generic-builder_vanagon-packaging_generic-builder/3088/

Note that the solaris-sparc failures are unrelated to this change, caused by the updation of package xz upstream. That works after updating the package requirement and running the build: https://jenkins-platform.delivery.puppetlabs.net/view/vanagon-generic-builder/job/platform_vanagon-generic-builder_vanagon-packaging_generic-builder/3094/

shubhamshinde360 commented 1 month ago

Superseded by: https://github.com/puppetlabs/puppet-runtime/pull/882

We have ruby-3.2.5 released with takes care of the CVE for main, so we only need to apply this gem update step for 7.x.