File tree Expand file tree Collapse file tree 10 files changed +37
-1
lines changed Expand file tree Collapse file tree 10 files changed +37
-1
lines changed Original file line number Diff line number Diff line change @@ -227,7 +227,7 @@ jobs:
227
227
run : mv image-scan-output image-build-logs/image-scan-output
228
228
229
229
- name : Fail if no images have passed scanning
230
- run : if [ $(wc -l < image-build-logs/image-scan-output/clean -images.txt) -le 0 ]; then exit 1; fi
230
+ run : if [ $(wc -l < image-build-logs/image-scan-output/critical -images.txt) -gt 0 ]; then exit 1; fi
231
231
if : ${{ !inputs.push-dirty }}
232
232
233
233
- name : Copy clean images to push-attempt-images list
Original file line number Diff line number Diff line change @@ -116,6 +116,15 @@ dnf_custom_repos_rocky_9:
116
116
gpgcheck : yes
117
117
username : " {{ stackhpc_repo_mirror_username | default(omit, true) }}"
118
118
password : " {{ stackhpc_repo_mirror_password | default(omit, true) }}"
119
+ security-common :
120
+ baseurl : " {{ stackhpc_repo_rocky_9_sig_security_common_url }}"
121
+ description : " Rocky Linux $releasever - SIG Security Common"
122
+ file : Rocky-SIG-Security-Common
123
+ gpgkey : " {{ rocky_9_sig_security_gpg_key }}"
124
+ gpgcheck : yes
125
+ includepkgs : " openssh*"
126
+ username : " {{ stackhpc_repo_mirror_username | default(omit, true) }}"
127
+ password : " {{ stackhpc_repo_mirror_password | default(omit, true) }}"
119
128
120
129
# Whether to enable EPEL repositories. This affects RedHat-based systems only.
121
130
dnf_enable_epel : " {{ dnf_install_epel | bool }}"
@@ -127,6 +136,7 @@ dnf_enable_elrepo_9: "{{ dnf_install_elrepo_9 | bool }}"
127
136
dnf_epel_9_gpg_key_url : " https://dl.fedoraproject.org/pub/epel/RPM-GPG-KEY-EPEL-9"
128
137
129
138
rocky_9_gpg_key : " https://dl.rockylinux.org/pub/rocky/RPM-GPG-KEY-Rocky-9"
139
+ rocky_9_sig_security_gpg_key : " https://dl.rockylinux.org/pub/sig/9/security/x86_64/security-common/RPM-GPG-KEY-Rocky-SIG-Security"
130
140
131
141
# Whether to install the epel-release package. This affects RedHat-based
132
142
# systems only. Default value is 'false'.
Original file line number Diff line number Diff line change @@ -50,6 +50,7 @@ stackhpc_repo_rocky_9_appstream_version: "{{ stackhpc_pulp_repo_rocky_9_appstrea
50
50
stackhpc_repo_rocky_9_extras_version : " {{ stackhpc_pulp_repo_rocky_9_extras_version }}"
51
51
stackhpc_repo_rocky_9_crb_version : " {{ stackhpc_pulp_repo_rocky_9_crb_version }}"
52
52
stackhpc_repo_rocky_9_highavailability_version : " {{ stackhpc_pulp_repo_rocky_9_highavailability_version }}"
53
+ stackhpc_repo_rocky_9_sig_security_common_version : " {{ stackhpc_pulp_repo_rocky_9_sig_security_common_version }}"
53
54
54
55
# Rocky-and-CI-specific Pulp urls
55
56
stackhpc_include_os_minor_version_in_repo_url : true
Original file line number Diff line number Diff line change @@ -70,6 +70,7 @@ stackhpc_repo_rocky_9_appstream_version: "{{ stackhpc_pulp_repo_rocky_9_appstrea
70
70
stackhpc_repo_rocky_9_extras_version : " {{ stackhpc_pulp_repo_rocky_9_extras_version }}"
71
71
stackhpc_repo_rocky_9_crb_version : " {{ stackhpc_pulp_repo_rocky_9_crb_version }}"
72
72
stackhpc_repo_rocky_9_highavailability_version : " {{ stackhpc_pulp_repo_rocky_9_highavailability_version }}"
73
+ stackhpc_repo_rocky_9_sig_security_common_version : " {{ stackhpc_pulp_repo_rocky_9_sig_security_common_version }}"
73
74
74
75
# Rocky-and-CI-specific Pulp urls
75
76
stackhpc_include_os_minor_version_in_repo_url : true
Original file line number Diff line number Diff line change @@ -47,6 +47,7 @@ stackhpc_repo_rocky_9_appstream_version: "{{ stackhpc_pulp_repo_rocky_9_appstrea
47
47
stackhpc_repo_rocky_9_extras_version : " {{ stackhpc_pulp_repo_rocky_9_extras_version }}"
48
48
stackhpc_repo_rocky_9_crb_version : " {{ stackhpc_pulp_repo_rocky_9_crb_version }}"
49
49
stackhpc_repo_rocky_9_highavailability_version : " {{ stackhpc_pulp_repo_rocky_9_highavailability_version }}"
50
+ stackhpc_repo_rocky_9_sig_security_common_version : " {{ stackhpc_pulp_repo_rocky_9_sig_security_common_version }}"
50
51
51
52
# Rocky-and-CI-specific Pulp urls
52
53
stackhpc_include_os_minor_version_in_repo_url : true
Original file line number Diff line number Diff line change @@ -31,6 +31,7 @@ stackhpc_pulp_repo_rocky_9_3_baseos_version: 20231215T005810
31
31
stackhpc_pulp_repo_rocky_9_3_crb_version : 20231215T005810
32
32
stackhpc_pulp_repo_rocky_9_3_extras_version : 20231211T120328
33
33
stackhpc_pulp_repo_rocky_9_3_highavailability_version : 20231214T005538
34
+ stackhpc_pulp_repo_rocky_9_sig_security_common_version : 20240708T235303
34
35
stackhpc_pulp_repo_ubuntu_jammy_security_version : 20231020T074329
35
36
stackhpc_pulp_repo_ubuntu_jammy_version : 20231020T074329
36
37
stackhpc_pulp_repo_ubuntu_cloud_archive_version : 20231019T125502
Original file line number Diff line number Diff line change @@ -272,6 +272,12 @@ stackhpc_pulp_rpm_repos:
272
272
base_path : " rocky/9/highavailability/x86_64/os/"
273
273
required : " {{ stackhpc_pulp_sync_rocky_9 | bool }}"
274
274
275
+ - name : Rocky Linux 9 - SIG Security Common
276
+ url : " {{ stackhpc_release_pulp_content_url }}/rocky/sig/9/security/x86_64/security-common/{{ stackhpc_pulp_repo_rocky_9_sig_security_common_version }}"
277
+ distribution_name : rocky-9-sig-security-common-
278
+ base_path : " rocky/sig/9/security/x86_64/security-common/"
279
+ required : " {{ stackhpc_pulp_sync_rocky_9 | bool }}"
280
+
275
281
# Additional CentOS Stream 9 repositories
276
282
- name : CentOS Stream 9 - NFV OpenvSwitch
277
283
url : " {{ stackhpc_release_pulp_content_url }}/centos/9-stream/nfv/x86_64/openvswitch-2/{{ stackhpc_pulp_repo_centos_stream_9_nfv_openvswitch_version }}"
Original file line number Diff line number Diff line change @@ -120,6 +120,10 @@ stackhpc_repo_rocky_9_extras_version: "{{ stackhpc_repo_distribution }}"
120
120
stackhpc_repo_rocky_9_highavailability_url : " {{ stackhpc_repo_mirror_url }}/pulp/content/rocky/{{ stackhpc_rocky_9_url_version }}/highavailability/x86_64/os/{{ stackhpc_repo_rocky_9_highavailability_version }}"
121
121
stackhpc_repo_rocky_9_highavailability_version : " {{ stackhpc_repo_distribution }}"
122
122
123
+ # Rocky 9 SIG Security Common
124
+ stackhpc_repo_rocky_9_sig_security_common_url : " {{ stackhpc_repo_mirror_url }}/pulp/content/rocky/sig/9/security/x86_64/security-common/{{ stackhpc_repo_rocky_9_sig_security_common_version }}"
125
+ stackhpc_repo_rocky_9_sig_security_common_version : " {{ stackhpc_repo_distribution }}"
126
+
123
127
# EPEL 9
124
128
stackhpc_repo_epel_9_url : " {{ stackhpc_repo_mirror_url }}/pulp/content/epel/9/Everything/x86_64/{{ stackhpc_repo_epel_9_version }}"
125
129
stackhpc_repo_epel_9_version : " {{ stackhpc_repo_distribution }}"
Original file line number Diff line number Diff line change
1
+ ---
2
+ security :
3
+ - |
4
+ Updates the Rocky Linux 9 SIG Security Common repository to address
5
+ `CVE-2024-6409 <https://sig-security.rocky.page/issues/CVE-2024-6409/>`__
6
+ in OpenSSH.
Original file line number Diff line number Diff line change
1
+ ---
2
+ security :
3
+ - |
4
+ Enables the Rocky Linux 9 SIG Security Common repository, which provides
5
+ updated OpenSSH packages addressing CVE-2024-6387 (regreSSHion). Other
6
+ packages available in this repository are currently ignored.
You can’t perform that action at this time.
0 commit comments