[ROB-2046] patched cve in disk tools#1913
Conversation
WalkthroughUpdated the default value of the DISK_TOOLS_IMAGE environment variable from "disk-tools:1.6" to "disk-tools:1.7". No other logic or environment variables were changed. Changes
Estimated code review effort🎯 1 (Trivial) | ⏱️ ~2 minutes ✨ Finishing Touches
🧪 Generate unit tests
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. 🪧 TipsChatThere are 3 ways to chat with CodeRabbit:
SupportNeed help? Create a ticket on our support page for assistance with any issues or questions. CodeRabbit Commands (Invoked using PR/Issue comments)Type Other keywords and placeholders
CodeRabbit Configuration File (
|
There was a problem hiding this comment.
Actionable comments posted: 0
🧹 Nitpick comments (1)
src/robusta/core/model/env_vars.py (1)
111-111: Consider pinning by digest for reproducible CVE postureTags can drift. If the intent is “this exact rebuilt image passed scans,” consider pinning the default to a sha256 digest (and still allow env override) or pin in Helm values.
📜 Review details
Configuration used: CodeRabbit UI
Review profile: CHILL
Plan: Pro
💡 Knowledge Base configuration:
- MCP integration is disabled by default for public repositories
- Jira integration is disabled by default for public repositories
- Linear integration is disabled by default for public repositories
You can enable these sources in your CodeRabbit configuration.
📒 Files selected for processing (1)
src/robusta/core/model/env_vars.py(1 hunks)
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (3)
- GitHub Check: run_tests
- GitHub Check: run_tests
- GitHub Check: Deploy docs
🔇 Additional comments (1)
src/robusta/core/model/env_vars.py (1)
111-111: Approve bump of DISK_TOOLS_IMAGE default to 1.7
No leftover references todisk-tools:1.6and no Helm value overrides detected.
I just rebuilt the image and the newer base removed the cves