Skip to content

Commit c4b9b1a

Browse files
committed
LCORE-1435: Vulnerabilities found in Konflux pipeline
1 parent ada8932 commit c4b9b1a

5 files changed

Lines changed: 159 additions & 222 deletions

File tree

Containerfile

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
# vim: set filetype=dockerfile
2-
ARG BUILDER_BASE_IMAGE=registry.access.redhat.com/ubi9/python-312
2+
ARG BUILDER_BASE_IMAGE=registry.access.redhat.com/ubi9/python-312:9.8-1781023618
33
ARG BUILDER_DNF_COMMAND=dnf
4-
ARG RUNTIME_BASE_IMAGE=registry.access.redhat.com/ubi9/python-312-minimal
4+
ARG RUNTIME_BASE_IMAGE=registry.access.redhat.com/ubi9/python-312-minimal:9.8-1781061228
55
ARG RUNTIME_DNF_COMMAND=microdnf
66

77
FROM ${BUILDER_BASE_IMAGE} AS builder
@@ -24,7 +24,7 @@ USER root
2424
# Install gcc - required by polyleven python package on aarch64
2525
# (dependency of autoevals, no pre-built binary wheels for linux on aarch64)
2626
# cmake and cargo are required by fastuuid, maturin
27-
RUN ${BUILDER_DNF_COMMAND} install -y --nodocs --setopt=keepcache=0 --setopt=tsflags=nodocs gcc gcc-c++ cmake cargo
27+
RUN ${BUILDER_DNF_COMMAND} install -y --nodocs --setopt=keepcache=0 --setopt=tsflags=nodocs gcc g++ cmake cargo
2828

2929
# Install uv package manager
3030
RUN pip3.12 install "uv>=0.8.15"

redhat.repo

Lines changed: 0 additions & 69 deletions
This file was deleted.

rpms.in.yaml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,12 +1,12 @@
11
packages:
22
[
33
gcc,
4-
gcc-c++,
4+
g++,
55
jq,
66
patch,
77
cmake,
88
cargo,
99
]
1010
contentOrigin:
11-
repofiles: ["./redhat.repo"]
11+
repofiles: ["./ubi.repo"]
1212
arches: [x86_64, aarch64]

rpms.lock.yaml

Lines changed: 92 additions & 148 deletions
Original file line numberDiff line numberDiff line change
@@ -4,177 +4,121 @@ lockfileVendor: redhat
44
arches:
55
- arch: aarch64
66
packages:
7-
- url: https://cdn.redhat.com/content/eus/rhel9/9.6/aarch64/appstream/os/Packages/c/cargo-1.84.1-1.el9.aarch64.rpm
8-
repoid: rhel-9-for-aarch64-appstream-eus-rpms
9-
size: 7744425
10-
checksum: sha256:5db626d49748f31fb02916c24fa1a7e5759ce7b905ac3e781d42079fba8fa1c4
7+
- url: https://cdn-ubi.redhat.com/content/public/ubi/dist/ubi9/9/aarch64/appstream/os/Packages/c/cargo-1.92.0-1.el9.aarch64.rpm
8+
repoid: ubi-9-for-aarch64-appstream-rpms
9+
size: 8530651
10+
checksum: sha256:14ac2d264369b0ac4442d6b773224765413282ea996dac29cf576c176c8cdcba
1111
name: cargo
12-
evr: 1.84.1-1.el9
13-
sourcerpm: rust-1.84.1-1.el9.src.rpm
14-
- url: https://cdn.redhat.com/content/eus/rhel9/9.6/aarch64/appstream/os/Packages/c/cmake-3.26.5-2.el9.aarch64.rpm
15-
repoid: rhel-9-for-aarch64-appstream-eus-rpms
16-
size: 7432689
17-
checksum: sha256:6ac0e5e9a4fd761f8688678ac83580c7eebeacf6c241bd8089d72c4a477b22c3
12+
evr: 1.92.0-1.el9
13+
sourcerpm: rust-1.92.0-1.el9.src.rpm
14+
- url: https://cdn-ubi.redhat.com/content/public/ubi/dist/ubi9/9/aarch64/appstream/os/Packages/c/cmake-3.31.8-3.el9.aarch64.rpm
15+
repoid: ubi-9-for-aarch64-appstream-rpms
16+
size: 11655593
17+
checksum: sha256:2a77fe1c3784083dcdebdd548c16d823b3e4a5adb8d6c00e36841aa633eab53b
1818
name: cmake
19-
evr: 3.26.5-2.el9
20-
sourcerpm: cmake-3.26.5-2.el9.src.rpm
21-
- url: https://cdn.redhat.com/content/eus/rhel9/9.6/aarch64/appstream/os/Packages/c/cmake-data-3.26.5-2.el9.noarch.rpm
22-
repoid: rhel-9-for-aarch64-appstream-eus-rpms
23-
size: 2488227
24-
checksum: sha256:84da65a7b8921f031d15903d91c5967022620f9e96b7493c8ab8024014755ee7
19+
evr: 3.31.8-3.el9
20+
sourcerpm: cmake-3.31.8-3.el9.src.rpm
21+
- url: https://cdn-ubi.redhat.com/content/public/ubi/dist/ubi9/9/aarch64/appstream/os/Packages/c/cmake-data-3.31.8-3.el9.noarch.rpm
22+
repoid: ubi-9-for-aarch64-appstream-rpms
23+
size: 2829291
24+
checksum: sha256:1cdc2e88a996c575b750483c8f562674e4b50a6ab414c7bbe6f6b641c1db7bd9
2525
name: cmake-data
26-
evr: 3.26.5-2.el9
27-
sourcerpm: cmake-3.26.5-2.el9.src.rpm
28-
- url: https://cdn.redhat.com/content/eus/rhel9/9.6/aarch64/appstream/os/Packages/c/cmake-rpm-macros-3.26.5-2.el9.noarch.rpm
29-
repoid: rhel-9-for-aarch64-appstream-eus-rpms
30-
size: 12250
31-
checksum: sha256:1c74969c8a4f21851f5b89f25ac55c689b75bed1318d0435fc3a14a49c39d0e3
32-
name: cmake-rpm-macros
33-
evr: 3.26.5-2.el9
34-
sourcerpm: cmake-3.26.5-2.el9.src.rpm
35-
- url: https://cdn.redhat.com/content/eus/rhel9/9.6/aarch64/appstream/os/Packages/g/gcc-c++-11.5.0-5.el9_5.aarch64.rpm
36-
repoid: rhel-9-for-aarch64-appstream-eus-rpms
37-
size: 12999288
38-
checksum: sha256:a9ff0bd2a2b3483e07dcf87f8137a6358f36f5300c934b90500f119f884e3463
39-
name: gcc-c++
40-
evr: 11.5.0-5.el9_5
41-
sourcerpm: gcc-11.5.0-5.el9_5.src.rpm
42-
- url: https://cdn.redhat.com/content/eus/rhel9/9.6/aarch64/appstream/os/Packages/l/libstdc++-devel-11.5.0-5.el9_5.aarch64.rpm
43-
repoid: rhel-9-for-aarch64-appstream-eus-rpms
44-
size: 2526795
45-
checksum: sha256:83a2006137335a9b17a05a02a54481abcdfd295b280b924c51caaacd7bf07ad6
46-
name: libstdc++-devel
47-
evr: 11.5.0-5.el9_5
48-
sourcerpm: gcc-11.5.0-5.el9_5.src.rpm
49-
- url: https://cdn.redhat.com/content/eus/rhel9/9.6/aarch64/appstream/os/Packages/l/libuv-1.42.0-2.el9_4.aarch64.rpm
50-
repoid: rhel-9-for-aarch64-appstream-eus-rpms
26+
evr: 3.31.8-3.el9
27+
sourcerpm: cmake-3.31.8-3.el9.src.rpm
28+
- url: https://cdn-ubi.redhat.com/content/public/ubi/dist/ubi9/9/aarch64/appstream/os/Packages/l/libuv-1.42.0-2.el9_4.aarch64.rpm
29+
repoid: ubi-9-for-aarch64-appstream-rpms
5130
size: 150129
5231
checksum: sha256:4dc8a40da74e0f9823356460ee11f183c70f382953700fffef0c448198a677cc
5332
name: libuv
5433
evr: 1:1.42.0-2.el9_4
5534
sourcerpm: libuv-1.42.0-2.el9_4.src.rpm
56-
- url: https://cdn.redhat.com/content/eus/rhel9/9.6/aarch64/appstream/os/Packages/p/patch-2.7.6-16.el9.aarch64.rpm
57-
repoid: rhel-9-for-aarch64-appstream-eus-rpms
58-
size: 129037
59-
checksum: sha256:335c720da3caa41822737dd431d91a4adc79c85dedbe4483ecaf58bc83767610
60-
name: patch
61-
evr: 2.7.6-16.el9
62-
sourcerpm: patch-2.7.6-16.el9.src.rpm
63-
- url: https://cdn.redhat.com/content/eus/rhel9/9.6/aarch64/appstream/os/Packages/r/rust-1.84.1-1.el9.aarch64.rpm
64-
repoid: rhel-9-for-aarch64-appstream-eus-rpms
65-
size: 26093725
66-
checksum: sha256:5be9185a7d684022bc0686049c22ef901c4df6dce2822bdec16a1a47c46b6861
35+
- url: https://cdn-ubi.redhat.com/content/public/ubi/dist/ubi9/9/aarch64/appstream/os/Packages/o/oniguruma-6.9.6-1.el9.5.aarch64.rpm
36+
repoid: ubi-9-for-aarch64-appstream-rpms
37+
size: 222582
38+
checksum: sha256:bc2305dad655ddb94f966158112efd6cefa6824d5aa2e80f63881f16cee74598
39+
name: oniguruma
40+
evr: 6.9.6-1.el9.5
41+
sourcerpm: oniguruma-6.9.6-1.el9.5.src.rpm
42+
- url: https://cdn-ubi.redhat.com/content/public/ubi/dist/ubi9/9/aarch64/appstream/os/Packages/r/rust-1.92.0-1.el9.aarch64.rpm
43+
repoid: ubi-9-for-aarch64-appstream-rpms
44+
size: 29421295
45+
checksum: sha256:43a1b0f5168a39ceea3fd90d42b23bc05d006d639cd35cfdad82a4f94aa58453
6746
name: rust
68-
evr: 1.84.1-1.el9
69-
sourcerpm: rust-1.84.1-1.el9.src.rpm
70-
- url: https://cdn.redhat.com/content/eus/rhel9/9.6/aarch64/appstream/os/Packages/r/rust-std-static-1.84.1-1.el9.aarch64.rpm
71-
repoid: rhel-9-for-aarch64-appstream-eus-rpms
72-
size: 39259196
73-
checksum: sha256:5889bced81144c4ea201085e5bfd040300c56048e5d7987e9eb69d4d252f87bf
47+
evr: 1.92.0-1.el9
48+
sourcerpm: rust-1.92.0-1.el9.src.rpm
49+
- url: https://cdn-ubi.redhat.com/content/public/ubi/dist/ubi9/9/aarch64/appstream/os/Packages/r/rust-std-static-1.92.0-1.el9.aarch64.rpm
50+
repoid: ubi-9-for-aarch64-appstream-rpms
51+
size: 41493155
52+
checksum: sha256:3b3a70a8e11f53559c4b84927ebd0565a073052bac2c53edda6cb328bfb28090
7453
name: rust-std-static
75-
evr: 1.84.1-1.el9
76-
sourcerpm: rust-1.84.1-1.el9.src.rpm
77-
- url: https://cdn.redhat.com/content/eus/rhel9/9.6/aarch64/baseos/os/Packages/e/ed-1.14.2-12.el9.aarch64.rpm
78-
repoid: rhel-9-for-aarch64-baseos-eus-rpms
79-
size: 78931
80-
checksum: sha256:3bce4ce6243886c448e58f589b79e3ac829fcde53d1ff13d5906a8cdc22be091
81-
name: ed
82-
evr: 1.14.2-12.el9
83-
sourcerpm: ed-1.14.2-12.el9.src.rpm
84-
- url: https://cdn.redhat.com/content/eus/rhel9/9.6/aarch64/baseos/os/Packages/i/info-6.7-15.el9.aarch64.rpm
85-
repoid: rhel-9-for-aarch64-baseos-eus-rpms
86-
size: 230301
87-
checksum: sha256:c5ae65876c73c6f4e240081431745f5ba0a91d10a4bfb8a5d162ca3d6f039202
88-
name: info
89-
evr: 6.7-15.el9
90-
sourcerpm: texinfo-6.7-15.el9.src.rpm
54+
evr: 1.92.0-1.el9
55+
sourcerpm: rust-1.92.0-1.el9.src.rpm
56+
- url: https://cdn-ubi.redhat.com/content/public/ubi/dist/ubi9/9/aarch64/baseos/os/Packages/j/jq-1.6-19.el9_8.2.aarch64.rpm
57+
repoid: ubi-9-for-aarch64-baseos-rpms
58+
size: 191195
59+
checksum: sha256:633aaf3e87b19d4a591bd9f47cd81fde8ec49629d3f58932addfc8a134b7949d
60+
name: jq
61+
evr: 1.6-19.el9_8.2
62+
sourcerpm: jq-1.6-19.el9_8.2.src.rpm
9163
source: []
9264
module_metadata: []
9365
- arch: x86_64
9466
packages:
95-
- url: https://cdn.redhat.com/content/eus/rhel9/9.6/x86_64/appstream/os/Packages/c/cargo-1.84.1-1.el9.x86_64.rpm
96-
repoid: rhel-9-for-x86_64-appstream-eus-rpms
97-
size: 8292467
98-
checksum: sha256:7dd011cd79a635654ade4e3186c5f7545d692de81157d1ce1d42656eaa6993b2
67+
- url: https://cdn-ubi.redhat.com/content/public/ubi/dist/ubi9/9/x86_64/appstream/os/Packages/c/cargo-1.92.0-1.el9.x86_64.rpm
68+
repoid: ubi-9-for-x86_64-appstream-rpms
69+
size: 9100626
70+
checksum: sha256:3c4afc2cb56734d01aaaaa8d0c317688f6fe143ad239079342f4fe9b631ded0f
9971
name: cargo
100-
evr: 1.84.1-1.el9
101-
sourcerpm: rust-1.84.1-1.el9.src.rpm
102-
- url: https://cdn.redhat.com/content/eus/rhel9/9.6/x86_64/appstream/os/Packages/c/cmake-3.26.5-2.el9.x86_64.rpm
103-
repoid: rhel-9-for-x86_64-appstream-eus-rpms
104-
size: 9159462
105-
checksum: sha256:f553370cb02b87e7388697468256556e765b102c2fcb56be6bc250cb2351e8ad
72+
evr: 1.92.0-1.el9
73+
sourcerpm: rust-1.92.0-1.el9.src.rpm
74+
- url: https://cdn-ubi.redhat.com/content/public/ubi/dist/ubi9/9/x86_64/appstream/os/Packages/c/cmake-3.31.8-3.el9.x86_64.rpm
75+
repoid: ubi-9-for-x86_64-appstream-rpms
76+
size: 13989883
77+
checksum: sha256:e67ea7aef1edd470e4ec22982e97871655abcdc0990754d4e8f147d4e7de317a
10678
name: cmake
107-
evr: 3.26.5-2.el9
108-
sourcerpm: cmake-3.26.5-2.el9.src.rpm
109-
- url: https://cdn.redhat.com/content/eus/rhel9/9.6/x86_64/appstream/os/Packages/c/cmake-data-3.26.5-2.el9.noarch.rpm
110-
repoid: rhel-9-for-x86_64-appstream-eus-rpms
111-
size: 2488227
112-
checksum: sha256:84da65a7b8921f031d15903d91c5967022620f9e96b7493c8ab8024014755ee7
79+
evr: 3.31.8-3.el9
80+
sourcerpm: cmake-3.31.8-3.el9.src.rpm
81+
- url: https://cdn-ubi.redhat.com/content/public/ubi/dist/ubi9/9/x86_64/appstream/os/Packages/c/cmake-data-3.31.8-3.el9.noarch.rpm
82+
repoid: ubi-9-for-x86_64-appstream-rpms
83+
size: 2829291
84+
checksum: sha256:1cdc2e88a996c575b750483c8f562674e4b50a6ab414c7bbe6f6b641c1db7bd9
11385
name: cmake-data
114-
evr: 3.26.5-2.el9
115-
sourcerpm: cmake-3.26.5-2.el9.src.rpm
116-
- url: https://cdn.redhat.com/content/eus/rhel9/9.6/x86_64/appstream/os/Packages/c/cmake-rpm-macros-3.26.5-2.el9.noarch.rpm
117-
repoid: rhel-9-for-x86_64-appstream-eus-rpms
118-
size: 12250
119-
checksum: sha256:1c74969c8a4f21851f5b89f25ac55c689b75bed1318d0435fc3a14a49c39d0e3
120-
name: cmake-rpm-macros
121-
evr: 3.26.5-2.el9
122-
sourcerpm: cmake-3.26.5-2.el9.src.rpm
123-
- url: https://cdn.redhat.com/content/eus/rhel9/9.6/x86_64/appstream/os/Packages/g/gcc-c++-11.5.0-5.el9_5.x86_64.rpm
124-
repoid: rhel-9-for-x86_64-appstream-eus-rpms
125-
size: 13479598
126-
checksum: sha256:b8392274e302d665bc132aee4ed023f8a777d9c446531679ede18150d7867189
127-
name: gcc-c++
128-
evr: 11.5.0-5.el9_5
129-
sourcerpm: gcc-11.5.0-5.el9_5.src.rpm
130-
- url: https://cdn.redhat.com/content/eus/rhel9/9.6/x86_64/appstream/os/Packages/l/libstdc++-devel-11.5.0-5.el9_5.x86_64.rpm
131-
repoid: rhel-9-for-x86_64-appstream-eus-rpms
132-
size: 2531717
133-
checksum: sha256:84695eeeb1daa8ff74baf7efd9fc57fb136bec7e8a2ca56c105be6d83ec22d07
134-
name: libstdc++-devel
135-
evr: 11.5.0-5.el9_5
136-
sourcerpm: gcc-11.5.0-5.el9_5.src.rpm
137-
- url: https://cdn.redhat.com/content/eus/rhel9/9.6/x86_64/appstream/os/Packages/l/libuv-1.42.0-2.el9_4.x86_64.rpm
138-
repoid: rhel-9-for-x86_64-appstream-eus-rpms
86+
evr: 3.31.8-3.el9
87+
sourcerpm: cmake-3.31.8-3.el9.src.rpm
88+
- url: https://cdn-ubi.redhat.com/content/public/ubi/dist/ubi9/9/x86_64/appstream/os/Packages/l/libuv-1.42.0-2.el9_4.x86_64.rpm
89+
repoid: ubi-9-for-x86_64-appstream-rpms
13990
size: 154427
14091
checksum: sha256:e1fab39251239ccaad2fb4dbe6c55ec1ae60f76d4ae81582b06e6a58e30879b2
14192
name: libuv
14293
evr: 1:1.42.0-2.el9_4
14394
sourcerpm: libuv-1.42.0-2.el9_4.src.rpm
144-
- url: https://cdn.redhat.com/content/eus/rhel9/9.6/x86_64/appstream/os/Packages/p/patch-2.7.6-16.el9.x86_64.rpm
145-
repoid: rhel-9-for-x86_64-appstream-eus-rpms
146-
size: 133240
147-
checksum: sha256:d2e0307a2d1d4eff0c2db406841030461b35864926916f2a92244427d89316be
148-
name: patch
149-
evr: 2.7.6-16.el9
150-
sourcerpm: patch-2.7.6-16.el9.src.rpm
151-
- url: https://cdn.redhat.com/content/eus/rhel9/9.6/x86_64/appstream/os/Packages/r/rust-1.84.1-1.el9.x86_64.rpm
152-
repoid: rhel-9-for-x86_64-appstream-eus-rpms
153-
size: 28050444
154-
checksum: sha256:9ba3c53fd811af2f294e31360d75e33e4cb89893130c7b3fe0c6191e20a09f3e
95+
- url: https://cdn-ubi.redhat.com/content/public/ubi/dist/ubi9/9/x86_64/appstream/os/Packages/o/oniguruma-6.9.6-1.el9.5.x86_64.rpm
96+
repoid: ubi-9-for-x86_64-appstream-rpms
97+
size: 226331
98+
checksum: sha256:6c884cc2216e5b4699ebd8cde27b39e99532520b367f645ed6cc660d081916dc
99+
name: oniguruma
100+
evr: 6.9.6-1.el9.5
101+
sourcerpm: oniguruma-6.9.6-1.el9.5.src.rpm
102+
- url: https://cdn-ubi.redhat.com/content/public/ubi/dist/ubi9/9/x86_64/appstream/os/Packages/r/rust-1.92.0-1.el9.x86_64.rpm
103+
repoid: ubi-9-for-x86_64-appstream-rpms
104+
size: 31511504
105+
checksum: sha256:fbc70b11f38999206d70a104789d1f7f21ca9f9090c7a73d6db337bff4f5205b
155106
name: rust
156-
evr: 1.84.1-1.el9
157-
sourcerpm: rust-1.84.1-1.el9.src.rpm
158-
- url: https://cdn.redhat.com/content/eus/rhel9/9.6/x86_64/appstream/os/Packages/r/rust-std-static-1.84.1-1.el9.x86_64.rpm
159-
repoid: rhel-9-for-x86_64-appstream-eus-rpms
160-
size: 41211472
161-
checksum: sha256:73bb90884432e2b43758f1043f107a570b5d54b38f17d5d0af51bac103ceb4f5
107+
evr: 1.92.0-1.el9
108+
sourcerpm: rust-1.92.0-1.el9.src.rpm
109+
- url: https://cdn-ubi.redhat.com/content/public/ubi/dist/ubi9/9/x86_64/appstream/os/Packages/r/rust-std-static-1.92.0-1.el9.x86_64.rpm
110+
repoid: ubi-9-for-x86_64-appstream-rpms
111+
size: 42991765
112+
checksum: sha256:d286394aaa75a796a06db130d2a980bee8e6ab4cbaa38a3b84e12379fbae4671
162113
name: rust-std-static
163-
evr: 1.84.1-1.el9
164-
sourcerpm: rust-1.84.1-1.el9.src.rpm
165-
- url: https://cdn.redhat.com/content/eus/rhel9/9.6/x86_64/baseos/os/Packages/e/ed-1.14.2-12.el9.x86_64.rpm
166-
repoid: rhel-9-for-x86_64-baseos-eus-rpms
167-
size: 79993
168-
checksum: sha256:5fb3c625fd1ace94f133522bdaf4768abd78f029e20886b8e4aed2d6d1aac664
169-
name: ed
170-
evr: 1.14.2-12.el9
171-
sourcerpm: ed-1.14.2-12.el9.src.rpm
172-
- url: https://cdn.redhat.com/content/eus/rhel9/9.6/x86_64/baseos/os/Packages/i/info-6.7-15.el9.x86_64.rpm
173-
repoid: rhel-9-for-x86_64-baseos-eus-rpms
174-
size: 233806
175-
checksum: sha256:3643f98b45cc973073096608aaa45976d722fe284590ff7c1d5f93ad77ba0f8b
176-
name: info
177-
evr: 6.7-15.el9
178-
sourcerpm: texinfo-6.7-15.el9.src.rpm
114+
evr: 1.92.0-1.el9
115+
sourcerpm: rust-1.92.0-1.el9.src.rpm
116+
- url: https://cdn-ubi.redhat.com/content/public/ubi/dist/ubi9/9/x86_64/baseos/os/Packages/j/jq-1.6-19.el9_8.2.x86_64.rpm
117+
repoid: ubi-9-for-x86_64-baseos-rpms
118+
size: 197453
119+
checksum: sha256:9793a39a4746a09ba89c3d9ccc70150ac6c878286deee26d7e3aabede4666417
120+
name: jq
121+
evr: 1.6-19.el9_8.2
122+
sourcerpm: jq-1.6-19.el9_8.2.src.rpm
179123
source: []
180124
module_metadata: []

0 commit comments

Comments
 (0)