Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

promtail: update promtail base image to debian:bullseye-slim #4516

Merged
merged 1 commit into from
Oct 22, 2021

Conversation

lizzzcai
Copy link
Contributor

What this PR does / why we need it:
Update the base image of promtail to keep the image secure.
From debian:buster-slim to debian:bullseye-slim
Which issue(s) this PR fixes:
Fixes #4140

Special notes for your reviewer:
docker scan report before the update:

Package manager:   deb
Project name:      docker-image|grafana/promtail
Docker image:      grafana/promtail:update-promtail-base-image-517ba7c
Platform:          linux/amd64
Base image:        debian:10.11-slim

Tested 89 dependencies for known vulnerabilities, found 62 vulnerabilities.

Base Image         Vulnerabilities  Severity
debian:10.11-slim  60               2 critical, 8 high, 6 medium, 44 low

Recommendations for base image upgrade:

Major upgrades
Base Image      Vulnerabilities  Severity
debian:11-slim  35               1 critical, 0 high, 1 medium, 33 low

docker scan report after the update:

Package manager:   deb
Project name:      docker-image|grafana/promtail
Docker image:      grafana/promtail:update-promtail-base-image-517ba7c-WIP
Platform:          linux/amd64
Base image:        debian:11.1-slim

Tested 100 dependencies for known vulnerabilities, found 35 vulnerabilities.

According to our scan, you are currently using the most secure version of the selected base image

Checklist

  • Documentation added
  • Tests updated

@lizzzcai lizzzcai requested a review from a team as a code owner October 21, 2021 10:50
@CLAassistant
Copy link

CLAassistant commented Oct 21, 2021

CLA assistant check
All committers have signed the CLA.

@owen-d owen-d merged commit 69819c2 into grafana:main Oct 22, 2021
@lizzzcai lizzzcai deleted the update-promtail-base-image branch October 22, 2021 13:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Security: base image promtail has a lot of vulnerabilities
3 participants