Skip to content
This repository was archived by the owner on Sep 30, 2024. It is now read-only.

Update all wolfi base images#55310

Merged
willdollman merged 3 commits intomainfrom
will-vincent/update-base-images-5-1-5
Jul 26, 2023
Merged

Update all wolfi base images#55310
willdollman merged 3 commits intomainfrom
will-vincent/update-base-images-5-1-5

Conversation

@willdollman
Copy link
Contributor

@willdollman willdollman commented Jul 26, 2023

Update all base images to patch new vulnerabilities for the 5.1.5 release.

  • Update base images
  • Update grafana base images (updated separately)

Test plan

@cla-bot cla-bot bot added the cla-signed label Jul 26, 2023
@willdollman
Copy link
Contributor Author

Before updating, running Trivy against sourcegraph/wolfiwolfi-server-base reported 9 vulns (8 medium, 1 high), and the grafana image reported several distinct vulns.

After the update, both the sourcegraph/wolfi-server-base and wolfi-grafana images report 0 vulns using trivy.

@willdollman willdollman merged commit f0c6a20 into main Jul 26, 2023
@willdollman willdollman deleted the will-vincent/update-base-images-5-1-5 branch July 26, 2023 14:07
@github-actions
Copy link
Contributor

The backport to 5.1 failed:

The process '/usr/bin/git' failed with exit code 1

To backport manually, run these commands in your terminal:

# Fetch latest updates from GitHub
git fetch
# Create a new working tree
git worktree add .worktrees/backport-5.1 5.1
# Navigate to the new working tree
cd .worktrees/backport-5.1
# Create a new branch
git switch --create backport-55310-to-5.1
# Cherry-pick the merged commit of this pull request and resolve the conflicts
git cherry-pick -x --mainline 1 f0c6a207752f982eef2623f49d1c94b56679ed75
# Push it to GitHub
git push --set-upstream origin backport-55310-to-5.1
# Go back to the original working tree
cd ../..
# Delete the working tree
git worktree remove .worktrees/backport-5.1

Then, create a pull request where the base branch is 5.1 and the compare/head branch is backport-55310-to-5.1.

@github-actions github-actions bot added backports failed-backport-to-5.1 release-blocker Prevents us from releasing: https://about.sourcegraph.com/handbook/engineering/releases labels Jul 26, 2023
willdollman added a commit that referenced this pull request Jul 26, 2023
Update all base images to patch new vulnerabilities for the 5.1.5
release.

- [x] Update base images
- [x] Update grafana base images (updated separately)

<!-- All pull requests REQUIRE a test plan:
https://docs.sourcegraph.com/dev/background-information/testing_principles
-->

- [x] CI (main-dry-run)
https://buildkite.com/sourcegraph/sourcegraph/builds/236063
- [x] Manual vulnerability scanning of images

(cherry picked from commit f0c6a20)
@willdollman
Copy link
Contributor Author

Backported manually in https://github.com/sourcegraph/sourcegraph/pull/55318

MaedahBatool pushed a commit that referenced this pull request Jul 28, 2023
Update all base images to patch new vulnerabilities for the 5.1.5
release.

- [x] Update base images
- [x] Update grafana base images (updated separately)

## Test plan

<!-- All pull requests REQUIRE a test plan:
https://docs.sourcegraph.com/dev/background-information/testing_principles
-->

- [x] CI (main-dry-run)
https://buildkite.com/sourcegraph/sourcegraph/builds/236063
- [x] Manual vulnerability scanning of images
davejrt pushed a commit that referenced this pull request Aug 9, 2023
Update all base images to patch new vulnerabilities for the 5.1.5
release.

- [x] Update base images
- [x] Update grafana base images (updated separately)

## Test plan

<!-- All pull requests REQUIRE a test plan:
https://docs.sourcegraph.com/dev/background-information/testing_principles
-->

- [x] CI (main-dry-run)
https://buildkite.com/sourcegraph/sourcegraph/builds/236063
- [x] Manual vulnerability scanning of images
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

backports cla-signed release-blocker Prevents us from releasing: https://about.sourcegraph.com/handbook/engineering/releases

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants