Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Patch shell version to v0.1.26 #790

Merged
merged 1 commit into from
Aug 8, 2024
Merged

Conversation

w13915984028
Copy link
Member

@w13915984028 w13915984028 commented Aug 7, 2024

Problem:

harvester/harvester#6283

Solution:

Bump shell version to elimate/reduce CVE

manually cherry-pick from PR #766

Related Issue:
harvester/harvester#6283

Test plan:

Signed-off-by: Jian Wang <jian.wang@suse.com>
@bk201
Copy link
Member

bk201 commented Aug 7, 2024

Should we bump the monitoring and logging chart too?

@w13915984028
Copy link
Member Author

@bk201

When v1.3.2 is only targeting for those must fix, then those considerations not to bump chart now:

(1) CVE fluentbit image has been 2.2.0 from Harvester v1.3.1; the PR #766 removes the patch to rancher-monitoring as upstream finally be in same version with Harvester.
(2) CVE shell version, bump to latest v0.1.26 in this PR #790; in v1.3.1 it was v0.1.22.

(3) PR #766 includes the eventrouter target v0.3.1 for Harvester v1.4.0; in Harvester v1.3.1 it was v0.2.0
(4) A known issue harvester/harvester#6272 needs to be fixed and backported to v1.3.2; then we can safely bump monitoring&logging chart in v1.4.0

If you target to release minor image tags for all Harvester components like harvester/harvester#6158, then I will rethink this PR.

@bk201 bk201 requested a review from tserong August 7, 2024 09:25
@bk201 bk201 merged commit b31f20b into harvester:v1.3 Aug 8, 2024
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants