Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade dependencies 2024-09-16 #6570

Closed
36 tasks done
azul-group opened this issue Sep 16, 2024 · 1 comment
Closed
36 tasks done

Upgrade dependencies 2024-09-16 #6570

azul-group opened this issue Sep 16, 2024 · 1 comment
Assignees
Labels
- [priority] Medium debt [type] A defect incurring continued engineering cost enh [type] New feature or request infra [subject] Project infrastructure like CI/CD, build and deployment scripts no demo [process] Not to be demonstrated at the end of the sprint operator [process] To be addressed by whoever is operator orange [process] Done by the Azul team

Comments

@azul-group
Copy link
Collaborator

azul-group commented Sep 16, 2024

  • Update PyCharm image
    • Bump base image tag (only same Debian release), if possible
    • Bump upstream version, if possible
    • Bump internal version
    • Remove unused dependencies with high or critical CVEs
    • Push commit to GitHub (directly to master branch, no PR needed)
    • GH Action workflow succeeded
    • Image is available on DockerHub
  • Update Elasticsearch image
    • Bump base image tag (only minor and patch versions), if possible
    • Bump internal version
    • Remove unused dependencies with high or critical CVEs
    • Push commit to GitHub (directly to main branch, no PR needed)
    • GH Action workflow succeeded
    • Image is available on DockerHub
  • Update BigQuery Emulator image
    • Bump base image tag, if possible
    • Bump internal version
    • Push commit to GitHub (directly to azul branch, no PR needed)
    • GH Action workflow succeeded
    • Image is available on DockerHub
  • Create Azul PR, connected to this issue, with …
  • Created tickets for any deferred updates to …
    • … to next major or minor Python version or such ticket already exists
    • … to next major Docker version or such ticket already exists
    • … to next major or minor Terraform version or such ticket already exists
@azul-group azul-group added debt [type] A defect incurring continued engineering cost enh [type] New feature or request infra [subject] Project infrastructure like CI/CD, build and deployment scripts operator [process] To be addressed by whoever is operator orange [process] Done by the Azul team labels Sep 16, 2024
@dsotirho-ucsc dsotirho-ucsc self-assigned this Sep 16, 2024
@dsotirho-ucsc dsotirho-ucsc added the - [priority] Medium label Sep 16, 2024
dsotirho-ucsc added a commit to DataBiosphere/azul-docker-pycharm that referenced this issue Sep 17, 2024
dsotirho-ucsc added a commit to DataBiosphere/azul-docker-elasticsearch that referenced this issue Sep 17, 2024
dsotirho-ucsc added a commit to DataBiosphere/azul-bigquery-emulator that referenced this issue Sep 17, 2024
dsotirho-ucsc added a commit to DataBiosphere/azul-docker-elasticsearch that referenced this issue Sep 17, 2024
…/azul#6570)

xmlsec was updated to 2.2.6 in elasticsearch 7.17.24, and no longer has the CVE-2021-40690 vulnerability that xmlsec 2.1.4 had
dsotirho-ucsc added a commit that referenced this issue Sep 17, 2024
dsotirho-ucsc added a commit that referenced this issue Sep 17, 2024
dsotirho-ucsc added a commit that referenced this issue Sep 17, 2024
dsotirho-ucsc added a commit that referenced this issue Sep 20, 2024
@hannes-ucsc hannes-ucsc added the no demo [process] Not to be demonstrated at the end of the sprint label Sep 20, 2024
dsotirho-ucsc added a commit that referenced this issue Sep 20, 2024
@dsotirho-ucsc
Copy link
Contributor

Google sheet: Inspector findings (tab: 2024-09-16)

Screenshot 2024-09-23 at 2 29 10 PM

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
- [priority] Medium debt [type] A defect incurring continued engineering cost enh [type] New feature or request infra [subject] Project infrastructure like CI/CD, build and deployment scripts no demo [process] Not to be demonstrated at the end of the sprint operator [process] To be addressed by whoever is operator orange [process] Done by the Azul team
Projects
None yet
Development

No branches or pull requests

3 participants