-
Bug
-
Resolution: Done
-
Major
-
ACM 2.11.0
-
1
-
False
-
None
-
False
-
https://github.com/stolostron/multicluster-observability-operator/pull/1498, https://github.com/stolostron/observatorium-operator/pull/154, https://github.com/stolostron/observatorium/pull/96, https://github.com/stolostron/thanos-receive-controller/pull/23, https://github.com/stolostron/thanos/pull/111, https://github.com/stolostron/kube-state-metrics/pull/59, https://github.com/stolostron/prometheus-operator/pull/47, https://github.com/stolostron/prometheus-alertmanager/pull/66, https://github.com/stolostron/grafana/pull/127
-
-
-
MCO Sprint 24
-
Critical
-
No
Description of problem:
Need to ensure that CVE-2023-45288 is patched for all Observability images:
upgrade go pkg golang.org/x/net to v0.23.0 or above
Observability Repos:
https://github.com/stolostron/multicluster-observability-operator
https://github.com/stolostron/observatorium-operator/
https://github.com/stolostron/observatorium
https://github.com/stolostron/thanos-receive-controller
https://github.com/stolostron/thanos
https://github.com/stolostron/kube-rbac-proxy - already at v0.26.0
https://github.com/stolostron/kube-state-metrics
https://github.com/stolostron/prometheus - already at v0.24.0
https://github.com/stolostron/prometheus-operator
https://github.com/stolostron/prometheus-alertmanager
https://github.com/stolostron/node-exporter - already at v0.23.0
https://github.com/stolostron/grafana
Version-Release number of selected component (if applicable):
How reproducible:
Steps to Reproduce:
- ...
Actual results:
Expected results:
Additional info:
- is cloned by
-
ACM-12258 [release-2.10] Observability: fix CVE-2023-45288 if necessary
- Closed