← Back to team overview

ubuntu-docker-images team mailing list archive

Re: redis contains outdated Ubuntu packages

 

Rebuild and retagged!

On Tue, Oct 18, 2022 at 2:15 AM <security-team-toolbox-bot@xxxxxxxxxxxxx>
wrote:

> A scan of this rock shows that it was built with packages from the Ubuntu
> archive that have since received security updates. The following lists new
> USNs for affected binary packages in each rock revision:
>
> Revision r38cea9c3a3e2 (s390x; channels: latest, 6.0-22.04_beta, edge,
> 6.0-22.04_edge)
>  * zlib1g: 5570-2
>
> Revision r44c816b9322e (ppc64le; channels: latest, 6.0-22.04_beta, edge,
> 6.0-22.04_edge)
>  * zlib1g: 5570-2
>
> Revision r640d8ec29c92 (ppc64le; channels: 5.0-20.04_edge, 5.0-20.04_beta)
>  * zlib1g: 5570-2
>
> Revision r7a8a44600986 (amd64; channels: latest, 6.0-22.04_beta, edge,
> 6.0-22.04_edge)
>  * zlib1g: 5570-2
>
> Revision rabe88043ce01 (arm64; channels: 5.0-20.04_edge, 5.0-20.04_beta)
>  * zlib1g: 5570-2
>
> Revision rc4ba45977ee1 (s390x; channels: 5.0-20.04_edge, 5.0-20.04_beta)
>  * zlib1g: 5570-2
>
> Revision reefa739bdbcd (amd64; channels: 5.0-20.04_edge, 5.0-20.04_beta)
>  * zlib1g: 5570-2
>
> Revision rf0c8dfa64827 (arm64; channels: latest, 6.0-22.04_beta, edge,
> 6.0-22.04_edge)
>  * zlib1g: 5570-2
>
> Simply rebuilding the rock will pull in the new security updates and
> resolve this. If your rock also contains vendored code, now might be a
> good time to review it for any needed updates.
>
> Thank you for your rock and for attending to this matter.
>
> References:
>  * https://ubuntu.com/security/notices/USN-5570-2/
>

Follow ups

References