Dependencies updated or ignored for CVE vulnerabilities#2173
Dependencies updated or ignored for CVE vulnerabilities#2173elelaysh wants to merge 2 commits intostackhpc/2025.1from
Conversation
d90bbda to
c50bc98
Compare
There was a problem hiding this comment.
Code Review
This pull request updates several dependencies to address CVEs and ignores others with justifications. The dependency updates for etcd, cadvisor, and prometheus-msteams look correct. The CVE suppressions are also in line with the descriptions. My main feedback is to add the justifications for ignoring CVEs as comments in the allowed-vulnerabilities.yml file. This will improve the maintainability of the configuration by making it self-documenting, explaining why certain vulnerabilities are considered acceptable risks in this context.
|
Cherry-picked 3c961f2 from stackhpc/2024.1 |
|
@elelaysh are you going to rebuild against this spec, or do the current containers conform to this? |
c50bc98 to
a1e1c6f
Compare
Yes: I need to rebuild:
|
7a9361a to
d6b3ac6
Compare
|
Rebuilt container images with tag 2025.1-rocky-9-20260303T104901: https://github.com/stackhpc/stackhpc-kayobe-config/actions/runs/22619571977 |
bump cadvisor to 0.56.2
Ignore CVE-2024-24790 in prometheus mtail exporter
control plane is trusted
Bump grafana to 12.3.3 to fix CVE-2025-68121
grafana server 12.3.3 is fixed but the opensearch-datasource plugin is still affected.
Bump etcd to 3.5.27 to fix CVE-2025-68121
Ignore CVE-2025-68121 for prometheus images
Ignore CVE-2025-68121 for influxdb
No new version is available and it runs on a secure network
Ignore CVE-2025-68121 for letsencrypt-lego
it only talks to known servers
Ignore CVE-2025-68121 for neutron
report caused by docker client and we don't speak to remote docker over tls
Ignore CVE-2026-27699 for opensearch-dashboard
basic-ftp@5.0.5 is present in opensearch-dashboards 2.19.4