Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

alpine: bump 3.20.2 (CVE-2024-5535) #17225

Merged
merged 2 commits into from
Jul 22, 2024
Merged

Conversation

ncopa
Copy link
Contributor

@ncopa ncopa commented Jul 22, 2024

No description provided.

@ncopa ncopa requested a review from a team as a code owner July 22, 2024 15:00

This comment has been minimized.

LaurentGoderre
LaurentGoderre previously approved these changes Jul 22, 2024
@tianon
Copy link
Member

tianon commented Jul 22, 2024

Are you planning to rebuild all the versions? They're all affected: alpinelinux/docker-alpine#405 (comment)

@ncopa ncopa marked this pull request as draft July 22, 2024 18:27
@ncopa
Copy link
Contributor Author

ncopa commented Jul 22, 2024

Are you planning to rebuild all the versions? They're all affected: alpinelinux/docker-alpine#405 (comment)

yes. I'm working on it. I can push them into this PR.

@ncopa ncopa requested a review from LaurentGoderre July 22, 2024 18:35
@ncopa ncopa marked this pull request as ready for review July 22, 2024 18:35
Copy link

Diff for 427ff87:
diff --git a/_bashbrew-cat b/_bashbrew-cat
index e41c2b4..d92a12e 100644
--- a/_bashbrew-cat
+++ b/_bashbrew-cat
@@ -1,10 +1,10 @@
 Maintainers: Natanael Copa <[email protected]> (@ncopa)
 GitRepo: https://github.com/alpinelinux/docker-alpine.git
 
-Tags: 3.17.8, 3.17
+Tags: 3.17.9, 3.17
 Architectures: amd64, arm32v6, arm32v7, arm64v8, i386, ppc64le, s390x
 GitFetch: refs/heads/v3.17
-GitCommit: 7b631cf259b81eec0f59e8f3cccac479c702d2c1
+GitCommit: efaaa8fee828ca129b2ca85104dd2f96a35f93dc
 amd64-Directory: x86_64
 arm32v6-Directory: armhf
 arm32v7-Directory: armv7
@@ -13,10 +13,10 @@ i386-Directory: x86
 ppc64le-Directory: ppc64le
 s390x-Directory: s390x
 
-Tags: 3.18.7, 3.18
+Tags: 3.18.8, 3.18
 Architectures: amd64, arm32v6, arm32v7, arm64v8, i386, ppc64le, s390x
 GitFetch: refs/heads/v3.18
-GitCommit: fb6cd4d1c0fc2b1b73c34a445d120c02c82752cd
+GitCommit: 19842e73b6c42f620a710957101663da79870a37
 amd64-Directory: x86_64
 arm32v6-Directory: armhf
 arm32v7-Directory: armv7
@@ -25,10 +25,10 @@ i386-Directory: x86
 ppc64le-Directory: ppc64le
 s390x-Directory: s390x
 
-Tags: 3.19.2, 3.19
+Tags: 3.19.3, 3.19
 Architectures: amd64, arm32v6, arm32v7, arm64v8, i386, ppc64le, s390x
 GitFetch: refs/heads/v3.19
-GitCommit: 0ea45484ad78078c51350293201cec8650c2f6bf
+GitCommit: e18b92255654f757419d5e7f45e917d4ad787a68
 amd64-Directory: x86_64
 arm32v6-Directory: armhf
 arm32v7-Directory: armv7
@@ -37,10 +37,10 @@ i386-Directory: x86
 ppc64le-Directory: ppc64le
 s390x-Directory: s390x
 
-Tags: 3.20.1, 3.20, 3, latest
+Tags: 3.20.2, 3.20, 3, latest
 Architectures: amd64, arm32v6, arm32v7, arm64v8, i386, ppc64le, riscv64, s390x
 GitFetch: refs/heads/v3.20
-GitCommit: d796f6cbd6ffa3aeb21f6e5a783c20b61dba64dd
+GitCommit: 3b06e21a03a8564bb1b261da824b9e2cfa6e8bdf
 amd64-Directory: x86_64
 arm32v6-Directory: armhf
 arm32v7-Directory: armv7
diff --git a/_bashbrew-list b/_bashbrew-list
index 105ecc9..449aeac 100644
--- a/_bashbrew-list
+++ b/_bashbrew-list
@@ -1,12 +1,12 @@
 alpine:3
 alpine:3.17
-alpine:3.17.8
+alpine:3.17.9
 alpine:3.18
-alpine:3.18.7
+alpine:3.18.8
 alpine:3.19
-alpine:3.19.2
+alpine:3.19.3
 alpine:3.20
-alpine:3.20.1
+alpine:3.20.2
 alpine:20240606
 alpine:edge
 alpine:latest
diff --git a/alpine_3.17/Dockerfile b/alpine_3.17/Dockerfile
index 50cb2e1..d2b5a59 100644
--- a/alpine_3.17/Dockerfile
+++ b/alpine_3.17/Dockerfile
@@ -1,3 +1,3 @@
 FROM scratch
-ADD alpine-minirootfs-3.17.8-x86_64.tar.gz /
+ADD alpine-minirootfs-3.17.9-x86_64.tar.gz /
 CMD ["/bin/sh"]
diff --git a/alpine_3.18/alpine-minirootfs-3.18.7-x86_64.tar.gz b/alpine_3.17/alpine-minirootfs-3.17.9-x86_64.tar.gz
similarity index 33%
rename from alpine_3.18/alpine-minirootfs-3.18.7-x86_64.tar.gz
rename to alpine_3.17/alpine-minirootfs-3.17.9-x86_64.tar.gz
index 5b77984..9733dbb 100644
Binary files a/alpine_3.18/alpine-minirootfs-3.18.7-x86_64.tar.gz and b/alpine_3.17/alpine-minirootfs-3.17.9-x86_64.tar.gz differ
diff --git a/alpine_3.17/alpine-minirootfs-3.17.8-x86_64.tar.gz  'tar -t' b/alpine_3.17/alpine-minirootfs-3.17.9-x86_64.tar.gz  'tar -t'
similarity index 100%
rename from alpine_3.17/alpine-minirootfs-3.17.8-x86_64.tar.gz  'tar -t'
rename to alpine_3.17/alpine-minirootfs-3.17.9-x86_64.tar.gz  'tar -t'
diff --git a/alpine_3.18/Dockerfile b/alpine_3.18/Dockerfile
index 46ad675..13348a9 100644
--- a/alpine_3.18/Dockerfile
+++ b/alpine_3.18/Dockerfile
@@ -1,3 +1,3 @@
 FROM scratch
-ADD alpine-minirootfs-3.18.7-x86_64.tar.gz /
+ADD alpine-minirootfs-3.18.8-x86_64.tar.gz /
 CMD ["/bin/sh"]
diff --git a/alpine_3.17/alpine-minirootfs-3.17.8-x86_64.tar.gz b/alpine_3.18/alpine-minirootfs-3.18.8-x86_64.tar.gz
similarity index 33%
rename from alpine_3.17/alpine-minirootfs-3.17.8-x86_64.tar.gz
rename to alpine_3.18/alpine-minirootfs-3.18.8-x86_64.tar.gz
index 3f6fe52..132a0e9 100644
Binary files a/alpine_3.17/alpine-minirootfs-3.17.8-x86_64.tar.gz and b/alpine_3.18/alpine-minirootfs-3.18.8-x86_64.tar.gz differ
diff --git a/alpine_3.18/alpine-minirootfs-3.18.7-x86_64.tar.gz  'tar -t' b/alpine_3.18/alpine-minirootfs-3.18.8-x86_64.tar.gz  'tar -t'
similarity index 100%
rename from alpine_3.18/alpine-minirootfs-3.18.7-x86_64.tar.gz  'tar -t'
rename to alpine_3.18/alpine-minirootfs-3.18.8-x86_64.tar.gz  'tar -t'
diff --git a/alpine_3.19/Dockerfile b/alpine_3.19/Dockerfile
index 51abb3c..0530175 100644
--- a/alpine_3.19/Dockerfile
+++ b/alpine_3.19/Dockerfile
@@ -1,3 +1,3 @@
 FROM scratch
-ADD alpine-minirootfs-3.19.2-x86_64.tar.gz /
+ADD alpine-minirootfs-3.19.3-x86_64.tar.gz /
 CMD ["/bin/sh"]
diff --git a/alpine_3.19/alpine-minirootfs-3.19.2-x86_64.tar.gz b/alpine_3.19/alpine-minirootfs-3.19.3-x86_64.tar.gz
similarity index 33%
rename from alpine_3.19/alpine-minirootfs-3.19.2-x86_64.tar.gz
rename to alpine_3.19/alpine-minirootfs-3.19.3-x86_64.tar.gz
index 7bf4003..c17d417 100644
Binary files a/alpine_3.19/alpine-minirootfs-3.19.2-x86_64.tar.gz and b/alpine_3.19/alpine-minirootfs-3.19.3-x86_64.tar.gz differ
diff --git a/alpine_3.19/alpine-minirootfs-3.19.2-x86_64.tar.gz  'tar -t' b/alpine_3.19/alpine-minirootfs-3.19.3-x86_64.tar.gz  'tar -t'
similarity index 100%
rename from alpine_3.19/alpine-minirootfs-3.19.2-x86_64.tar.gz  'tar -t'
rename to alpine_3.19/alpine-minirootfs-3.19.3-x86_64.tar.gz  'tar -t'
diff --git a/alpine_latest/Dockerfile b/alpine_latest/Dockerfile
index bca352d..bc0e197 100644
--- a/alpine_latest/Dockerfile
+++ b/alpine_latest/Dockerfile
@@ -1,3 +1,3 @@
 FROM scratch
-ADD alpine-minirootfs-3.20.1-x86_64.tar.gz /
+ADD alpine-minirootfs-3.20.2-x86_64.tar.gz /
 CMD ["/bin/sh"]
diff --git a/alpine_latest/alpine-minirootfs-3.20.1-x86_64.tar.gz b/alpine_latest/alpine-minirootfs-3.20.2-x86_64.tar.gz
similarity index 34%
rename from alpine_latest/alpine-minirootfs-3.20.1-x86_64.tar.gz
rename to alpine_latest/alpine-minirootfs-3.20.2-x86_64.tar.gz
index 2f17faa..312abf7 100644
Binary files a/alpine_latest/alpine-minirootfs-3.20.1-x86_64.tar.gz and b/alpine_latest/alpine-minirootfs-3.20.2-x86_64.tar.gz differ
diff --git a/alpine_latest/alpine-minirootfs-3.20.1-x86_64.tar.gz  'tar -t' b/alpine_latest/alpine-minirootfs-3.20.2-x86_64.tar.gz  'tar -t'
similarity index 100%
rename from alpine_latest/alpine-minirootfs-3.20.1-x86_64.tar.gz  'tar -t'
rename to alpine_latest/alpine-minirootfs-3.20.2-x86_64.tar.gz  'tar -t'

Relevant Maintainers:

Copy link
Member

@tianon tianon left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you! Hopefully we can get in alpine:edge sometime soon too, but IMO a lot less urgent 🙇 ❤️

@tianon tianon merged commit 81d892d into docker-library:master Jul 22, 2024
10 checks passed
@ncopa ncopa deleted the alpine-3.20.2 branch July 23, 2024 10:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants