Skip to content

Commit cf69f07

Browse files
Upgrade kured to 1.14.2 for vendored go CVE-2023-39325 (#7275)
1 parent e0b3d80 commit cf69f07

4 files changed

Lines changed: 14 additions & 15 deletions

File tree

Lines changed: 6 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -1,25 +1,21 @@
1-
From 492288d56314c65316a6d6f50b4b79c2eb0b267e Mon Sep 17 00:00:00 2001
2-
From: Rachel Menge <rachelmenge@microsoft.com>
3-
Date: Wed, 8 Nov 2023 10:51:46 -0800
4-
Subject: [PATCH] kured-imagePullPolicy patch updated for 1.13.2
1+
From: Mandeep Plaha <mandeepplaha@microsoft.com>
2+
Date: Tue, 16 Jan 2024 12:57:00 -0800
3+
Subject: [PATCH] kured-imagePullPolicy patch updated for 1.14.2
54

65
---
76
kured-ds.yaml | 2 +-
87
1 file changed, 1 insertion(+), 1 deletion(-)
98

109
diff --git a/kured-ds.yaml b/kured-ds.yaml
11-
index 7721fa1..78322da 100644
10+
index 1f03c2c..9f0416f 100644
1211
--- a/kured-ds.yaml
1312
+++ b/kured-ds.yaml
1413
@@ -34,7 +34,7 @@ spec:
1514
# If you find yourself here wondering why there is no
1615
# :latest tag on Docker Hub,see the FAQ in the README
17-
image: ghcr.io/kubereboot/kured:1.13.2
16+
image: ghcr.io/kubereboot/kured:1.14.2
1817
- imagePullPolicy: IfNotPresent
1918
+ imagePullPolicy: Always
2019
securityContext:
2120
privileged: true # Give permission to nsenter /proc/1/ns/mnt
22-
ports:
23-
--
24-
2.17.1
25-
21+
readOnlyRootFilesystem: true

SPECS/kured/kured.signatures.json

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
{
22
"Signatures": {
3-
"kured-1.13.2-vendor.tar.gz": "be2c5510693081a35abf911fd1bf0b7f202b1e59e3857e6f889fa101756cb7b5",
4-
"kured-1.13.2.tar.gz": "9b90a12d2343387800f9e83690c01e2f2012b512c4b8d591334e78984b3a1528"
3+
"kured-1.14.2-vendor.tar.gz": "42cb8ada114c4415e17b8904f714678cbedba2c196f91e694f9eb5a51427e6d0",
4+
"kured-1.14.2.tar.gz": "bdf1cde40637039d643990c8c5a5dc8be643c11d05ee6139688bbab27868650d"
55
}
66
}

SPECS/kured/kured.spec

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -24,7 +24,7 @@
2424
%global debug_package %{nil}
2525
Summary: Kubernetes daemonset to perform safe automatic node reboots
2626
Name: kured
27-
Version: 1.13.2
27+
Version: 1.14.2
2828
Release: 1%{?dist}
2929
License: Apache-2.0
3030
Vendor: Microsoft Corporation
@@ -122,6 +122,9 @@ sed -i -e 's|image: .*|image: registry.opensuse.org/kubic/kured:%{version}|g' %{
122122
%{_datarootdir}/k8s-yaml/kured/kured.yaml
123123

124124
%changelog
125+
* Tue Jan 16 2024 Mandeep Plaha <mandeepplaha@microsoft.com> - 1.14.2-1
126+
- Upgrade to 1.14.2 for vendored go CVE-2023-39325
127+
125128
* Mon Nov 06 2023 Rachel Menge <rachelmenge@microsoft.com> - 1.13.2-1
126129
- Upgrade to 1.13.2 for vendored go CVEs
127130

cgmanifest.json

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -8411,8 +8411,8 @@
84118411
"type": "other",
84128412
"other": {
84138413
"name": "kured",
8414-
"version": "1.13.2",
8415-
"downloadUrl": "https://github.com/weaveworks/kured/archive/refs/tags/1.13.2.tar.gz"
8414+
"version": "1.14.2",
8415+
"downloadUrl": "https://github.com/weaveworks/kured/archive/refs/tags/1.14.2.tar.gz"
84168416
}
84178417
}
84188418
},

0 commit comments

Comments
 (0)