Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade dependencies 2024-10-14 #6629

Open
37 tasks done
azul-group opened this issue Oct 14, 2024 · 3 comments
Open
37 tasks done

Upgrade dependencies 2024-10-14 #6629

azul-group opened this issue Oct 14, 2024 · 3 comments
Assignees
Labels
- [priority] Medium debt [type] A defect incurring continued engineering cost enh [type] New feature or request infra [subject] Project infrastructure like CI/CD, build and deployment scripts no demo [process] Not to be demonstrated at the end of the sprint operator [process] To be addressed by whoever is operator orange [process] Done by the Azul team

Comments

@azul-group
Copy link
Collaborator

azul-group commented Oct 14, 2024

  • Add CL item about GitLab data volume increase to 250 GiB in dev and anvildev
  • Update PyCharm image
    • Bump base image tag (only same Debian release), if possible
    • Bump upstream version, if possible
    • Bump internal version
    • Remove unused dependencies with high or critical CVEs
    • Push commit to GitHub (directly to master branch, no PR needed)
    • GH Action workflow succeeded
    • Image is available on DockerHub
  • Update Elasticsearch image
    • Bump base image tag (only minor and patch versions), if possible
    • Bump internal version
    • Remove unused dependencies with high or critical CVEs
    • Push commit to GitHub (directly to main branch, no PR needed)
    • GH Action workflow succeeded
    • Image is available on DockerHub
  • Update BigQuery Emulator image
    • Bump base image tag, if possible
    • Bump internal version
    • Push commit to GitHub (directly to azul branch, no PR needed)
    • GH Action workflow succeeded
    • Image is available on DockerHub
  • Create Azul PR, connected to this issue, with …
  • Created tickets for any deferred updates to …
    • … to next major or minor Python version or such ticket already exists
    • … to next major Docker version or such ticket already exists
    • … to next major or minor Terraform version or such ticket already exists
@azul-group azul-group added debt [type] A defect incurring continued engineering cost enh [type] New feature or request infra [subject] Project infrastructure like CI/CD, build and deployment scripts operator [process] To be addressed by whoever is operator orange [process] Done by the Azul team labels Oct 14, 2024
@achave11-ucsc achave11-ucsc added the - [priority] Medium label Oct 14, 2024
dsotirho-ucsc added a commit to DataBiosphere/azul-docker-pycharm that referenced this issue Oct 16, 2024
dsotirho-ucsc added a commit to DataBiosphere/azul-docker-elasticsearch that referenced this issue Oct 16, 2024
dsotirho-ucsc added a commit to DataBiosphere/azul-bigquery-emulator that referenced this issue Oct 16, 2024
dsotirho-ucsc added a commit that referenced this issue Oct 16, 2024
dsotirho-ucsc added a commit that referenced this issue Oct 16, 2024
@hannes-ucsc hannes-ucsc added the no demo [process] Not to be demonstrated at the end of the sprint label Oct 18, 2024
@dsotirho-ucsc
Copy link
Contributor

Update Google Sheet: Inspector Findings (tab: 2024-10-14)

Screenshot 2024-10-21 at 4 19 40 PM

@hannes-ucsc
Copy link
Member

hannes-ucsc commented Nov 7, 2024

Findings sheet contains errors. CVE-2023-31484 affects two images, the sheet only lists one.

CleanShot 2024-11-07 at 11 30 13@2x

In the future, we need to ensure that we give Inspector enough time to scan all images. Apparently, one hour is not enough.

@hannes-ucsc
Copy link
Member

hannes-ucsc commented Nov 8, 2024

CleanShot 2024-11-07 at 23 04 12@2x

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
- [priority] Medium debt [type] A defect incurring continued engineering cost enh [type] New feature or request infra [subject] Project infrastructure like CI/CD, build and deployment scripts no demo [process] Not to be demonstrated at the end of the sprint operator [process] To be addressed by whoever is operator orange [process] Done by the Azul team
Projects
None yet
Development

No branches or pull requests

4 participants