Skip to content

Commit 09f7a38

Browse files
authored
Merge pull request #1701 from stackhpc/epoxy-cve-fix2
Fix Critical CVEs on Epoxy Kolla container images
2 parents 8af48f2 + a1cd811 commit 09f7a38

File tree

4 files changed

+37
-25
lines changed

4 files changed

+37
-25
lines changed

etc/kayobe/kolla-image-tags.yml

Lines changed: 2 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,5 @@
55
# TODO: Rebuild epoxy images
66
kolla_image_tags:
77
openstack:
8-
rocky-9: 2025.1-rocky-9-20250603T110500
9-
ubuntu-noble: 2025.1-ubuntu-noble-20250606T113506
10-
neutron_l3_agent:
11-
rocky-9: 2025.1-rocky-9-20250606T090153
8+
rocky-9: 2025.1-rocky-9-20250611T085217
9+
ubuntu-noble: 2025.1-ubuntu-noble-20250611T085217

etc/kayobe/kolla/kolla-build.conf

Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -14,3 +14,15 @@ build_args = {{ (kolla_build_args | default({})).items() | map('join', ':') | jo
1414
type = git
1515
location = https://github.com/stackhpc/requirements
1616
reference = stackhpc/{{ openstack_release }}
17+
18+
[etcd]
19+
version = 3.5.21
20+
sha256 = amd64:adddda4b06718e68671ffabff2f8cee48488ba61ad82900e639d108f2148501c,arm64:95bf6918623a097c0385b96f139d90248614485e781ec9bee4768dbb6c79c53f
21+
22+
[letsencrypt-lego]
23+
version = v4.23.1
24+
sha256 = amd64:1fd60b1fd59c239bed22719a5de402cb745d1f933540cb1ec196e2c03e6e8882,arm64:1114745108343286d4bff189b4bdee3cba9d07ebcacc673860d91ab951d31e0d
25+
26+
[magnum-conductor-plugin-helm]
27+
version = v3.18.2
28+
sha256 = amd64:c5deada86fe609deefdf40e9cbbe3da2f8cf3f6a4551a0ebe7886dc8fcf98bce,arm64:03181a494a0916b370a100a5b2536104963b095be53fb23d1e29b2afb1c7de8d

etc/kayobe/pulp-repo-versions.yml

Lines changed: 21 additions & 21 deletions
Original file line numberDiff line numberDiff line change
@@ -1,20 +1,24 @@
11
---
22
# This file is autogenerated by Ansible using the following workflow:
33
# https://github.com/stackhpc/stackhpc-release-train/actions/workflows/package-update-kayobe.yml
4-
stackhpc_pulp_repo_centos_stream_9_docker_version: 20250123T000657
5-
stackhpc_pulp_repo_centos_stream_9_nfv_openvswitch_version: 20250205T015600
4+
stackhpc_pulp_repo_centos_stream_9_docker_version: 20250531T002004
5+
stackhpc_pulp_repo_centos_stream_9_nfv_openvswitch_version: 20250528T022338
66
stackhpc_pulp_repo_centos_stream_9_opstools_version: 20231213T031318
7-
stackhpc_pulp_repo_centos_stream_9_storage_ceph_squid_version: 20250203T100829
8-
stackhpc_pulp_repo_docker_ce_ubuntu_noble_version: 20250131T133101
9-
stackhpc_pulp_repo_elrepo_9_version: 20250203T000038
10-
stackhpc_pulp_repo_epel_9_version: 20250204T071808
11-
stackhpc_pulp_repo_grafana_version: 20250204T090817
12-
stackhpc_pulp_repo_opensearch_2_x_version: 20241106T010702
13-
stackhpc_pulp_repo_opensearch_dashboards_2_x_version: 20241106T010702
14-
stackhpc_pulp_repo_rhel9_rabbitmq_erlang_version: 20250128T001826
15-
stackhpc_pulp_repo_rhel9_rabbitmq_server_version: 20241217T002152
16-
stackhpc_pulp_repo_rhel_9_influxdb_version: 20250125T002237
17-
stackhpc_pulp_repo_rhel_9_mariadb_10_11_version: 20250205T001351
7+
stackhpc_pulp_repo_centos_stream_9_storage_ceph_squid_version: 20250412T024303
8+
stackhpc_pulp_repo_docker_ce_ubuntu_noble_version: 20250604T001951
9+
stackhpc_pulp_repo_elrepo_9_version: 20250608T000535
10+
stackhpc_pulp_repo_epel_9_version: 20250609T000109
11+
stackhpc_pulp_repo_grafana_version: 20250609T005704
12+
stackhpc_pulp_repo_opensearch_2_x_version: 20250430T014638
13+
stackhpc_pulp_repo_opensearch_dashboards_2_x_version: 20250430T014638
14+
stackhpc_pulp_repo_rhel9_rabbitmq_erlang_version: 20250607T003941
15+
stackhpc_pulp_repo_rhel9_rabbitmq_server_version: 20250607T003941
16+
stackhpc_pulp_repo_rhel_9_4_doca_modules_version: 20241213T112245
17+
stackhpc_pulp_repo_rhel_9_4_doca_version: 20241211T153620
18+
stackhpc_pulp_repo_rhel_9_5_doca_modules_version: 20250115T150314
19+
stackhpc_pulp_repo_rhel_9_5_doca_version: 20241211T171301
20+
stackhpc_pulp_repo_rhel_9_influxdb_version: 20250529T023704
21+
stackhpc_pulp_repo_rhel_9_mariadb_10_11_version: 20250523T014203
1822
stackhpc_pulp_repo_rhel_9_rabbitmq_erlang_version: 20240711T091318
1923
stackhpc_pulp_repo_rhel_9_rabbitmq_server_version: 20240711T091318
2024
stackhpc_pulp_repo_rhel_9_treasuredata_5_version: 20241115T002028
@@ -43,11 +47,7 @@ stackhpc_pulp_repo_rocky_9_5_baseos_version: 20250201T125442
4347
stackhpc_pulp_repo_rocky_9_5_crb_version: 20250204T095037
4448
stackhpc_pulp_repo_rocky_9_5_extras_version: 20250122T025402
4549
stackhpc_pulp_repo_rocky_9_5_highavailability_version: 20250204T095037
46-
stackhpc_pulp_repo_rocky_9_sig_security_common_version: 20250128T024400
47-
stackhpc_pulp_repo_ubuntu_cloud_archive_version: 20250205T050034
48-
stackhpc_pulp_repo_ubuntu_noble_security_version: 20250205T090140
49-
stackhpc_pulp_repo_ubuntu_noble_version: 20250205T090140
50-
stackhpc_pulp_repo_rhel_9_4_doca_version: 20241211T153620
51-
stackhpc_pulp_repo_rhel_9_4_doca_modules_version: 20241213T112245
52-
stackhpc_pulp_repo_rhel_9_5_doca_version: 20241211T171301
53-
stackhpc_pulp_repo_rhel_9_5_doca_modules_version: 20250115T150314
50+
stackhpc_pulp_repo_rocky_9_sig_security_common_version: 20250222T040303
51+
stackhpc_pulp_repo_ubuntu_cloud_archive_version: 20250609T053359
52+
stackhpc_pulp_repo_ubuntu_noble_security_version: 20250609T094526
53+
stackhpc_pulp_repo_ubuntu_noble_version: 20250609T094526

etc/kayobe/trivy/allowed-vulnerabilities.yml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -35,6 +35,8 @@ prometheus_libvirt_exporter_allowed_vulnerabilities:
3535
prometheus_cadvisor_allowed_vulnerabilities:
3636
- CVE-2024-41110
3737
- CVE-2024-45337
38+
influxdb_allowed_vulnerabilities:
39+
- CVE-2024-45337
3840

3941
###############################################################################
4042
# Dummy variable to allow Ansible to accept this file.

0 commit comments

Comments
 (0)