Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(docker): upgrade base image for executor image #2561

Merged
merged 1 commit into from
Apr 1, 2020

Conversation

dustinspecker
Copy link
Contributor

@dustinspecker dustinspecker commented Apr 1, 2020

This upgrades the executor base image from debian:9.6-slim to
debian:10.3-slim. This fixes a number of CVEs. As of today,
debian:9.6-slim has 10 high, 11 medium, and 60 low CVEs [1], while
debian:10.3-slim has 0 high, 4 medium, and 43 low CVEs [2].

1 - https://snyk.io/test/docker/debian%3A9.6-slim
2 - https://snyk.io/test/docker/debian%3A10.3-slim

Checklist:

  • Either (a) I've created an enhancement proposal and discussed it with the community, (b) this is a bug fix, or (c) this is a chore.
  • The title of the PR is (a) conventional, (b) states what changed, and (c) suffixes the related issues number. E.g. "fix(controller): Updates such and such. Fixes #1234".
  • I have written unit and/or e2e tests for my change. PRs without these are unlike to be merged.
  • Optional. I've added My organization is added to the USERS.md.
  • I've signed the CLA and required builds are green.

This upgrades the executor base image from debian:9.6-slim to
debian:10.3-slim. This fixes a number of CVEs. As of today,
debian:9.6-slim has 10 high, 11 medium, and 60 low CVEs [1], while
debian:10.3-slim has 0 high, 4 medium, and 43 low CVEs [2].

1 - https://snyk.io/test/docker/debian%3A9.6-slim
2 - https://snyk.io/test/docker/debian%3A10.3-slim
@CLAassistant
Copy link

CLAassistant commented Apr 1, 2020

CLA assistant check
All committers have signed the CLA.

@codecov
Copy link

codecov bot commented Apr 1, 2020

Codecov Report

Merging #2561 into master will not change coverage.
The diff coverage is n/a.

Impacted file tree graph

@@           Coverage Diff           @@
##           master    #2561   +/-   ##
=======================================
  Coverage   11.21%   11.21%           
=======================================
  Files          75       75           
  Lines       31838    31838           
=======================================
  Hits         3571     3571           
  Misses      27783    27783           
  Partials      484      484

Continue to review full report at Codecov.

Legend - Click here to learn more
Δ = absolute <relative> (impact), ø = not affected, ? = missing data
Powered by Codecov. Last update c4efb8f...d696520. Read the comment docs.

@alexec
Copy link
Contributor

alexec commented Apr 1, 2020

LGTM

@alexec alexec merged commit 49801e3 into argoproj:master Apr 1, 2020
@dustinspecker dustinspecker deleted the upgrade-base-to-fix-cves branch April 1, 2020 21:40
@alexec alexec mentioned this pull request Apr 6, 2020
24 tasks
@simster7
Copy link
Member

Back-ported to 2.6 and 2.7

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants