Skip to content

Update Dockerfile operator-framework/ansible-operator to v1.34.0#1714

Merged
rooftopcellist merged 1 commit intoansible:develfrom
mattmiller87:patch-1
Feb 21, 2024
Merged

Update Dockerfile operator-framework/ansible-operator to v1.34.0#1714
rooftopcellist merged 1 commit intoansible:develfrom
mattmiller87:patch-1

Conversation

@mattmiller87
Copy link
Copy Markdown
Contributor

@mattmiller87 mattmiller87 commented Feb 15, 2024

Vulnerability scans against this image when deployed shows: CVE-2023-4911

https://quay.io/repository/operator-framework/ansible-operator/manifest/sha256:f08f675976f42dc3a8ebbb8482acea153a8f57232e2ee48940e3d40ca40d24d9?tab=vulnerabilities

It appears if https://github.com/ansible/awx-operator/blob/5f3d9ed96f05b25b3c7f38df550d9f2bce0ec199/Dockerfile#L1C14-L1C49 is updated to v1.34.0 this vulnerability is mitigated.

SUMMARY
ISSUE TYPE
  • Bug, Docs Fix or other nominal change
ADDITIONAL INFORMATION

@rooftopcellist
Copy link
Copy Markdown
Member

rooftopcellist commented Feb 21, 2024

It's odd that the sdk docs haven't been updated to include 1.34.0 yet.

But this is good to merge. We could update to 1.34.1 too as that is now available on https://quay.io/repository/operator-framework/ansible-operator?tab=tags&tag=latest

Nothing troubling in the changelog for 1.33:

@rooftopcellist rooftopcellist enabled auto-merge (squash) February 21, 2024 19:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants