← Back to team overview

ubuntu-docker-images team mailing list archive

Re: cassandra contains outdated Ubuntu packages

 

On Friday, March 11 2022, security-team-toolbox-bot@xxxxxxxxxxxxx wrote:

> A scan of this rock shows that it was built with packages from the Ubuntu
> archive that have since received security updates. The following lists new
> USNs for affected binary packages in each rock revision:
>
> Revision r0297a964eda1 (ppc64le; channels: 4.0-21.10_edge)
>  * libexpat1: 5320-1
>
> Revision r19222e56b1ff (ppc64le; channels: 4.0-20.04_beta)
>  * libexpat1: 5320-1
>
> Revision r42607f663dbf (amd64; channels: 4.0-20.04_beta)
>  * libexpat1: 5320-1
>
> Revision r46192d90cb03 (ppc64le; channels: edge, latest, 4.0-21.10_beta)
>  * libexpat1: 5320-1
>
> Revision r50edfc4376b1 (s390x; channels: 4.0-21.10_edge)
>  * libexpat1: 5320-1
>
> Revision r545e45027748 (arm64; channels: edge, latest, 4.0-21.10_beta)
>  * libexpat1: 5320-1
>
> Revision r5c4b679f1a85 (arm64; channels: 4.0-21.10_edge)
>  * libexpat1: 5320-1
>
> Revision r66e1685a51e1 (arm64; channels: 4.0-20.04_edge)
>  * libexpat1: 5320-1
>
> Revision r6f93cd4f48bf (amd64; channels: 4.0-21.10_edge)
>  * libexpat1: 5320-1
>
> Revision r72b84114955a (arm64; channels: 4.0-20.04_beta)
>  * libexpat1: 5320-1
>
> Revision r82c7b4c77f0d (ppc64le; channels: 4.0-20.04_edge)
>  * libexpat1: 5320-1
>
> Revision r8a1fca2a8f08 (s390x; channels: edge, latest, 4.0-21.10_beta)
>  * libexpat1: 5320-1
>
> Revision rb5f9a7927f11 (amd64; channels: 4.0-20.04_edge)
>  * libexpat1: 5320-1
>
> Revision re1da06aa8fa6 (s390x; channels: 4.0-20.04_edge)
>  * libexpat1: 5320-1
>
> Revision rec0b9d1e7995 (s390x; channels: 4.0-20.04_beta)
>  * libexpat1: 5320-1
>
> Revision rf45e133f21d3 (amd64; channels: edge, latest, 4.0-21.10_beta)
>  * libexpat1: 5320-1
>
> Simply rebuilding the rock will pull in the new security updates and
> resolve this. If your rock also contains vendored code, now might be a
> good time to review it for any needed updates.

These have been rebuilt and retagged.

Thanks,

-- 
Sergio
GPG key ID: E92F D0B3 6B14 F1F4 D8E0  EB2F 106D A1C8 C3CB BF14