-
Bug
-
Resolution: Done-Errata
-
Undefined
-
None
-
None
-
git-lfs-3.2.0-2.el9_2
-
None
-
None
-
ZStream
-
rhel-sst-pt-python-ruby-nodejs
-
ssg_core_services
-
3
-
Dev ack
-
False
-
-
None
-
None
-
Approved Blocker
-
None
The git-lfs binary is currently being shipped in the DevWorkspace Operator Project Clone container, which is a Red Hat product. The Operator FIPS Static Check CVP test is currently showing a warning that the git-lfs binary is not FIPS compliant, see https://issues.redhat.com/browse/CRW-6246. This test will become a gating test (i.e. we can't ship Devworkspace Operator unless the git-lfs binary becomes FIPS compliant) by the end of CY24 Q2.
I'm hopeful that in order for git-lfs to be FIPS compliant, some additional go compiler flags need to be added, something along the lines of:
CGO_ENABLED=1 GOEXPERIMENT=strictfipsruntime GOOS=linux GOARCH=${ARCH} GO111MODULE=on go build ... -tags strictfipsruntime
- blocks
-
CRW-6246 git-lfs binary used in DevWorkspace Operator Project Clone container is not FIPS compliant
- Open
- links to
-
RHBA-2024:138736 git-lfs update