Skip to content

Update Alpine Image to 3.18.x#3046

Merged
joe-elliott merged 2 commits intografana:mainfrom
joe-elliott:fix-3044
Oct 20, 2023
Merged

Update Alpine Image to 3.18.x#3046
joe-elliott merged 2 commits intografana:mainfrom
joe-elliott:fix-3044

Conversation

@joe-elliott
Copy link
Copy Markdown
Collaborator

What this PR does:
Updates our base image to 3.18.x to patch CVE-2022-48174

Which issue(s) this PR fixes:
Update the Alpine image to fix 3.18 for Tempo. We will need to build a new release to fix GET.

Checklist

  • Tests updated
  • Documentation added
  • CHANGELOG.md updated - the order of entries should be [CHANGE], [FEATURE], [ENHANCEMENT], [BUGFIX]

Signed-off-by: Joe Elliott <number101010@gmail.com>
Comment thread CHANGELOG.md Outdated
Co-authored-by: Koenraad Verheyden <koenraad.verheyden@posteo.net>
@joe-elliott joe-elliott merged commit b7f2956 into grafana:main Oct 20, 2023
@joe-elliott joe-elliott added type/bug Something isn't working backport release-v2.2 labels Oct 25, 2023
@github-actions
Copy link
Copy Markdown
Contributor

The backport to release-v2.2 failed:

The process '/usr/bin/git' failed with exit code 1

To backport manually, run these commands in your terminal:

# Fetch latest updates from GitHub
git fetch
# Create a new branch
git switch --create backport-3046-to-release-v2.2 origin/release-v2.2
# Cherry-pick the merged commit of this pull request and resolve the conflicts
git cherry-pick -x b7f29566bc2414d2b975acd264dc0725820c735d

When the conflicts are resolved, stage and commit the changes:

git add . && git cherry-pick --continue

If you have the GitHub CLI installed:

# Push the branch to GitHub:
git push --set-upstream origin backport-3046-to-release-v2.2
# Create the PR body template
PR_BODY=$(gh pr view 3046 --json body --template 'Backport b7f29566bc2414d2b975acd264dc0725820c735d from #3046{{ "\n\n---\n\n" }}{{ index . "body" }}')
# Create the PR on GitHub
echo "${PR_BODY}" | gh pr create --title "[release-v2.2] Update Alpine Image to 3.18.x" --body-file - --label "type/bug" --label "backport" --base release-v2.2 --milestone release-v2.2 --web

Or, if you don't have the GitHub CLI installed (we recommend you install it!):

# Push the branch to GitHub:
git push --set-upstream origin backport-3046-to-release-v2.2

# Create a pull request where the `base` branch is `release-v2.2` and the `compare`/`head` branch is `backport-3046-to-release-v2.2`.

# Remove the local backport branch
git switch main
git branch -D backport-3046-to-release-v2.2

joe-elliott added a commit that referenced this pull request Oct 25, 2023
* fix 3044

Signed-off-by: Joe Elliott <number101010@gmail.com>

* Update CHANGELOG.md

Co-authored-by: Koenraad Verheyden <koenraad.verheyden@posteo.net>

---------

Signed-off-by: Joe Elliott <number101010@gmail.com>
Co-authored-by: Koenraad Verheyden <koenraad.verheyden@posteo.net>
(cherry picked from commit b7f2956)
joe-elliott added a commit that referenced this pull request Oct 25, 2023
* fix 3044

Signed-off-by: Joe Elliott <number101010@gmail.com>

* Update CHANGELOG.md

Co-authored-by: Koenraad Verheyden <koenraad.verheyden@posteo.net>

---------

Signed-off-by: Joe Elliott <number101010@gmail.com>
Co-authored-by: Koenraad Verheyden <koenraad.verheyden@posteo.net>
(cherry picked from commit b7f2956)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

CVE-2022-48174 found in Grafana Enterprise Traces 2.2.2

2 participants