Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[release-1.26] Bump version to 1.26.9 #5942

Merged

Conversation

dashea
Copy link

@dashea dashea commented Jan 24, 2025

What type of PR is this?

/kind other

What this PR does / why we need it:

New release for changes for CVE-2024-11218

How to verify it

Which issue(s) this PR fixes:

Special notes for your reviewer:

Does this PR introduce a user-facing change?

None

@dashea dashea force-pushed the dshea-release-1.26.9 branch from 53f013a to 01331ef Compare January 24, 2025 19:02
@nalind
Copy link
Member

nalind commented Jan 24, 2025

Can you pull in this .cirrus.yml chunk?

@nalind
Copy link
Member

nalind commented Jan 24, 2025

/approve

Copy link
Contributor

openshift-ci bot commented Jan 24, 2025

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: dashea, nalind

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

[NO NEW TESTS NEEDED]

Signed-off-by: David Shea <dshea@redhat.com>
@dashea dashea force-pushed the dshea-release-1.26.9 branch from 01331ef to 344fa6e Compare January 24, 2025 19:19
@nalind
Copy link
Member

nalind commented Jan 24, 2025

Thanks!
/lgtm

@nalind
Copy link
Member

nalind commented Jan 24, 2025

/hold
Bot's supposed to wait for tests to finish before putting it in the merge pool.

@nalind
Copy link
Member

nalind commented Jan 24, 2025

/unhold

@openshift-merge-bot openshift-merge-bot bot merged commit 9aaa280 into containers:release-1.26 Jan 24, 2025
23 checks passed
@dashea dashea deleted the dshea-release-1.26.9 branch January 24, 2025 20:38
@TomSweeneyRedHat
Copy link
Member

@dashea @cevich I unfortunately don't have SSO access at the moment and can't double check, but do we need Buildah 1.26 for RHEL 8.6, or Buildah 1.27?

@dashea
Copy link
Author

dashea commented Jan 24, 2025

@TomSweeneyRedHat 1.26. Here's the last advisory we took care for for 8.6, updated to buildah-1.26.8: https://access.redhat.com/errata/RHSA-2024:8703

@dashea
Copy link
Author

dashea commented Jan 24, 2025

@TomSweeneyRedHat ...but podman in 8.6 uses buildah 1.27.

@TomSweeneyRedHat
Copy link
Member

@dashea, thanks! I had written down 1.27 on my notes for this CVE, and had forgotten that was the version vendored into Podman, yet Buildah itself was 1.26 on RHEL 8.6. So ugh, looks like we'll need both versions of Buildah updated.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants