-
Notifications
You must be signed in to change notification settings - Fork 2.4k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[v4.9] Bump Buildah to v1.33.11, fix CVE-2024-9676 #24375
base: v4.9
Are you sure you want to change the base?
[v4.9] Bump Buildah to v1.33.11, fix CVE-2024-9676 #24375
Conversation
Fixes CVE-2024-9676 in the Podman v4.9 release branch. [NO NEW TESTS NEEDED] Signed-off-by: tomsweeneyredhat <[email protected]>
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: TomSweeneyRedHat The full list of commands accepted by this bot can be found here. The pull request process is described here
Needs approval from an approver in each of these files:
Approvers can indicate their approval by writing |
f39 EOL date is 2024-11-12, do we want/need to cut another release for this? |
Also CI seems broken, I remember fixing this issue on main but I would need to go through the git log to find it so I rather wait until someone tells me we a new release here |
Nobody's asked us yet. I would prefer not to cut a new release. |
I'll let @mheon decide on cutting a new release. If so, I'll chase down the build issues. If not, we can just close this. |
We can PS about this tomorrow, but if the EOL is in two weeks it's probably not worth it. |
Fixes CVE-2024-9676 in the Podman v4.9 release branch.
Also addresses: CVE-2024-9675, CVE-2024-9407, and CVE-2024-9341
[NO NEW TESTS NEEDED]
Does this PR introduce a user-facing change?