← Back to team overview

ubuntu-docker-images team mailing list archive

Re: CVEs potentially affecting upstream based ROCKs

 

Hi Emilia,

On Fri, Jul 30, 2021 at 12:05:54PM -0300, Emilia Torino wrote:

[snip...]

To confirm if the 3 git trees were present in both upstream based rocks
we were considering, I locally got them (docker pull ubuntu/cortex &&
docker image save etc, same for telegraf) and in both cases I see the
upstream manifest empty. Is that correct?

There was an issue with how we parse URLs from the Go package index
page. I proposed fixes for that and I will rebuild those images. I will
let you know once the new imags get tagged.

Thanks for letting us know about this one.

[snip...]

We also agree prometheus, prometheus-alertmanager and grafana were out
of this initial services, as were based on snaps. Is that still correct?

I missed this one in my previous reply. Yes, this is still correct.
Cassandra is our new OCI which is also included in this group of snap
based images.

[snip...]

--
Athos Ribeiro


Follow ups

References