Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update sidecar versions and cve fixes #2304

Merged

Conversation

nikhilbarge
Copy link
Contributor

@nikhilbarge nikhilbarge commented Mar 24, 2023

What this PR does / why we need it:
PR intent to fix reported CVE's for csi sidecars.
This will update sidecar versions.

As reported CVE's fixed, creating new tag v2.7.2
CVE-2022-41723
CVE-2022-41721
CVE-2022-27664
CVE-2022-28948
CVE-2022-21698
CVE-2021-44716

Testing done:
running e2e test

Special notes for your reviewer:

Release note:

PR will update sidecar versions.

@k8s-ci-robot k8s-ci-robot added the do-not-merge/work-in-progress Indicates that a PR should not merge because it is a work in progress. label Mar 24, 2023
@k8s-ci-robot k8s-ci-robot added cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. needs-ok-to-test Indicates a PR that requires an org member to verify it is safe to test. labels Mar 24, 2023
@k8s-ci-robot
Copy link
Contributor

Hi @nikhilbarge. Thanks for your PR.

I'm waiting for a kubernetes-sigs member to verify that this patch is reasonable to test. If it is, they should reply with /ok-to-test on its own line. Until that is done, I will not automatically test new commits in this PR, but the usual testing commands by org members will still work. Regular contributors should join the org to skip this step.

Once the patch is verified, the new status will be reflected by the ok-to-test label.

I understand the commands that are listed here.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository.

@k8s-ci-robot k8s-ci-robot added the size/XS Denotes a PR that changes 0-9 lines, ignoring generated files. label Mar 24, 2023
@svcbot-qecnsdp
Copy link

Block vanilla build status: FAILURE 
Stage before exit: checkout 

@svcbot-qecnsdp
Copy link

File vanilla build status: FAILURE 
Stage before exit: checkout 

@nikhilbarge nikhilbarge force-pushed the update_sidecar_cve_fix branch from f72d14f to 7141e68 Compare March 24, 2023 19:21
@k8s-ci-robot k8s-ci-robot added size/S Denotes a PR that changes 10-29 lines, ignoring generated files. and removed size/XS Denotes a PR that changes 0-9 lines, ignoring generated files. labels Mar 24, 2023
@svcbot-qecnsdp
Copy link

Started vanilla Block pipeline... Build Number: 1809

@svcbot-qecnsdp
Copy link

Started vanilla file pipeline... Build Number: 794

@divyenpatel
Copy link
Member

/ok-to-test

@k8s-ci-robot k8s-ci-robot added ok-to-test Indicates a non-member PR verified by an org member that is safe to test. and removed needs-ok-to-test Indicates a PR that requires an org member to verify it is safe to test. labels Mar 24, 2023
@svcbot-qecnsdp
Copy link

Block vanilla build status: FAILURE 
Stage before exit: e2e-tests 
Jenkins E2E Test Results: 
------------------------------

Ran 1 of 638 Specs in 435.768 seconds
SUCCESS! -- 1 Passed | 0 Failed | 0 Pending | 637 Skipped
PASS

Ginkgo ran 1 suite in 9m57.862645834s
Test Suite Passed
--
------------------------------

Ran 13 of 638 Specs in 4930.195 seconds
SUCCESS! -- 13 Passed | 0 Failed | 0 Pending | 625 Skipped
PASS

Ginkgo ran 1 suite in 1h22m36.683350052s
Test Suite Passed
--

Ran 41 of 638 Specs in 1060.999 seconds
FAIL! -- 39 Passed | 2 Failed | 0 Pending | 597 Skipped


Ginkgo ran 1 suite in 18m8.41551227s

Test Suite Failed

@svcbot-qecnsdp
Copy link

File vanilla build status: SUCCESS 
Stage before exit: finally 
Jenkins E2E Test Results: 
------------------------------

Ran 38 of 638 Specs in 6716.048 seconds
SUCCESS! -- 38 Passed | 0 Failed | 0 Pending | 600 Skipped
PASS

Ginkgo ran 1 suite in 1h54m27.631051206s
Test Suite Passed

@nikhilbarge nikhilbarge changed the title WIP: Update sidecar versions and cve fixes Update sidecar versions and cve fixes Mar 25, 2023
@k8s-ci-robot k8s-ci-robot removed the do-not-merge/work-in-progress Indicates that a PR should not merge because it is a work in progress. label Mar 25, 2023
@nikhilbarge nikhilbarge force-pushed the update_sidecar_cve_fix branch from 7141e68 to 1114433 Compare March 25, 2023 07:56
@svcbot-qecnsdp
Copy link

Started vanilla Block pipeline... Build Number: 1811

@svcbot-qecnsdp
Copy link

Block vanilla build status: FAILURE 
Stage before exit: e2e-tests 
Jenkins E2E Test Results: 
------------------------------

Ran 1 of 638 Specs in 447.220 seconds
SUCCESS! -- 1 Passed | 0 Failed | 0 Pending | 637 Skipped
PASS

Ginkgo ran 1 suite in 9m9.775986521s
Test Suite Passed
--
------------------------------

Ran 13 of 638 Specs in 5178.371 seconds
SUCCESS! -- 13 Passed | 0 Failed | 0 Pending | 625 Skipped
PASS

Ginkgo ran 1 suite in 1h26m45.934803489s
Test Suite Passed
--

Ran 41 of 638 Specs in 1022.129 seconds
FAIL! -- 36 Passed | 5 Failed | 0 Pending | 597 Skipped


Ginkgo ran 1 suite in 17m29.492979794s

Test Suite Failed

@svcbot-qecnsdp
Copy link

Started vanilla file pipeline... Build Number: 795

@svcbot-qecnsdp
Copy link

File vanilla build status: SUCCESS 
Stage before exit: finally 
Jenkins E2E Test Results: 
------------------------------

Ran 38 of 638 Specs in 7824.753 seconds
SUCCESS! -- 38 Passed | 0 Failed | 0 Pending | 600 Skipped
PASS

Ginkgo ran 1 suite in 2h12m24.884427308s
Test Suite Passed

@divyenpatel
Copy link
Member

/lgtm

@k8s-ci-robot k8s-ci-robot added the lgtm "Looks good to me", indicates that a PR is ready to be merged. label Mar 28, 2023
@divyenpatel
Copy link
Member

/approve

@k8s-ci-robot
Copy link
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: divyenpatel, nikhilbarge

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@k8s-ci-robot k8s-ci-robot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Mar 28, 2023
@k8s-ci-robot k8s-ci-robot merged commit da070f8 into kubernetes-sigs:release-2.7 Mar 28, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
approved Indicates a PR has been approved by an approver from all required OWNERS files. cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. lgtm "Looks good to me", indicates that a PR is ready to be merged. ok-to-test Indicates a non-member PR verified by an org member that is safe to test. size/S Denotes a PR that changes 10-29 lines, ignoring generated files.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants