-
Notifications
You must be signed in to change notification settings - Fork 3
Upgrade dependencies 2025-07-07 (#7257, #7261) #7281
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
202cee9 to
0139551
Compare
Codecov ReportAll modified and coverable lines are covered by tests ✅
Additional details and impacted files@@ Coverage Diff @@
## develop #7281 +/- ##
========================================
Coverage 85.03% 85.03%
========================================
Files 156 156
Lines 22443 22443
========================================
Hits 19084 19084
Misses 3359 3359 ☔ View full report in Codecov by Sentry. 🚀 New features to boost your workflow:
|
10435ec to
31ca866
Compare
31ca866 to
09d9fbf
Compare
09d9fbf to
8a40991
Compare
8a40991 to
542fe77
Compare
| # For instructions on finding the latest CIS-hardened AMI, see | ||
| # OPERATOR.rst#upgrading-linux-ami | ||
| # | ||
| # CIS Amazon Linux 2 Kernel 4.14 Benchmark - Level 1 - v01 -4c096026-c6b0-440c-bd2f-6d34904e4fc6 |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This comment line is out of context. The "link" into the operator manual doesn't work. It's not a link in the first place, nor does the fragment point to any existing anchor. The correct link is https://github.com/DataBiosphere/azul/blob/develop/OPERATOR.rst#updating-the-ami-for-gitlab-instances but that scrolls to a different place so maybe we should just mention the section and forgo a link.
The comment is also stale and doesn't correspond to the AMI ID.
But most importantly, the command from the operator manual doesn't work. It returns no output. This raises the question as to how the AMI ID below was obtained and why the manual wasn't updated.
Connected issue: #7257, #7261
Checklist
Author
developupgrades/yyyy-mm-ddUpgrade dependencies yyyy-mm-ddAuthor (upgrading deployments)
make docker_images.jsonand committed the resulting changes or this PR does not modifyazul_docker_images, or any other variables referenced in the definition of that variableutag to commit title or this PR does not require upgrading deploymentsupgradeor does not require upgrading deploymentsdeploy:sharedor does not modifydocker_images.json, and does not require deploying thesharedcomponent for any other reasondeploy:gitlabor does not require deploying thegitlabcomponentbackup:gitlabdeploy:runneror does not require deploying therunnerimageAuthor (before every review)
develop, squashed fixups from prior reviewsmake requirements_updateor this PR does not modifyrequirements*.txt,common.mk,MakefileandDockerfileRtag to commit title or this PR does not modifyrequirements*.txtreqsor does not modifyrequirements*.txtmake integration_testpasses in personal deployment or this PR does not modify functionality that could affect the IT outcomeSystem administrator (after approval)
no demoOperator (before pushing merge the commit)
develop_select dev.shared && CI_COMMIT_REF_NAME=develop make -C terraform/shared apply_keep_unusedor this PR is not labeleddeploy:shared_select dev.gitlab && python scripts/create_gitlab_snapshot.py --no-restart(see operator manual for details) or this PR is not labeledbackup:gitlab_select dev.gitlab && CI_COMMIT_REF_NAME=develop make -C terraform/gitlab applyor this PR is not labeleddeploy:gitlab_select anvildev.shared && CI_COMMIT_REF_NAME=develop make -C terraform/shared apply_keep_unusedor this PR is not labeleddeploy:shared_select anvildev.gitlab && python scripts/create_gitlab_snapshot.py --no-restart(see operator manual for details) or this PR is not labeledbackup:gitlab_select anvildev.gitlab && CI_COMMIT_REF_NAME=develop make -C terraform/gitlab applyor this PR is not labeleddeploy:gitlabdeploy:gitlabdeploy:gitlabSystem administrator
dev.gitlabare complete or this PR is not labeleddeploy:gitlabanvildev.gitlabare complete or this PR is not labeleddeploy:gitlabOperator (before pushing merge the commit)
_select dev.gitlab && make -C terraform/gitlab/runneror this PR is not labeleddeploy:runner_select anvildev.gitlab && make -C terraform/gitlab/runneror this PR is not labeleddeploy:runnersandboxlabeldevanvildevsandboxdeploymentanvilboxdeploymentsandboxdeploymentanvilboxdeploymentptagsOperator (after pushing the merge commit)
devanvildevdevdevanvildevanvildev_select dev.shared && make -C terraform/shared applyor this PR is not labeleddeploy:shared_select anvildev.shared && make -C terraform/shared applyor this PR is not labeleddeploy:shareddevanvildevOperator
anvildev.sharedwas last deployedscripts/export_inspector_findings.pyagainstanvildev, imported results to Google Sheet and posted screenshot of relevant1 findings as a comment on the connected issue.deploy:shared,deploy:gitlab,deploy:runnerandbackup:gitlablabels to the next promotion PRs or this PR carries none of these labelsdeploy:shared,deploy:gitlab,deploy:runnerandbackup:gitlablabels, from the description of this PR to that of the next promotion PRs or this PR carries none of these labels1A relevant finding is a high or critical vulnerability in an image
that is used within the security boundary. Images not used within the boundary
are tracked in
azul.docker_imagesunder a key starting with_.System administrator
Shorthand for review comments
Lline is too longWline wrapping is wrongQbad quotesFother formatting problem