Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

DLPX-85142 Unpin tar from linux-pkg on 6.0/stage #280

Conversation

palash-gandhi
Copy link
Contributor

@palash-gandhi palash-gandhi commented Mar 13, 2023

This change unpins the tar package from 6.0/stage. It was added as part of DLPX-85006 in 6.0/release due to a CVE. We leave the infrastructure behind for future possibilities.
Not that branching for the new release has already completed, we are seeing some failures, unrelated to this change but that reminded me that we need to revert this on both these branches.

ab-pre-push -b misc-debs: http://selfservice.jenkins.delphix.com/job/appliance-build-orchestrator-pre-push/4834/

@palash-gandhi palash-gandhi force-pushed the dlpx/pr/pgandhi-delphix/df5b5c77-4713-45a0-9a1d-f733be0d080d branch from f6e519e to 7f5e46b Compare March 13, 2023 21:32
@palash-gandhi palash-gandhi changed the title QI-4560 Revert "DLPX-85006 CVE-2022-48303 found in virtualization affected package tar_1.30+dfsg-7ubuntu0.20.04.2 (#277)" DLPX-85142 Revert "DLPX-85006 CVE-2022-48303 found in virtualization affected package tar_1.30+dfsg-7ubuntu0.20.04.2 (#277)" Mar 13, 2023
@palash-gandhi palash-gandhi marked this pull request as ready for review March 13, 2023 21:35
@prakashsurya
Copy link
Contributor

We can do it this way, or we can preserve the misc-debs package, and just remove the tar package from it.. i.e. so it'd be empty.. the idea being, the "infrastructure" will be there if we need to do this in the future..

Do we have thoughts if it'd be useful to keep the package definition around, for potential future use? or remove it, and if needed later, it can be resurrected (like I did)?

Copy link
Contributor

@prakashsurya prakashsurya left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'll approve as-is.. the notion if we want to keep the "misc-debs package infrastructure" around can be answered outside of this PR.. and we can always resurrect it later, even if we remove it in this PR..

@palash-gandhi palash-gandhi force-pushed the dlpx/pr/pgandhi-delphix/df5b5c77-4713-45a0-9a1d-f733be0d080d branch from b4f9204 to 374cc3e Compare March 13, 2023 22:19
@palash-gandhi palash-gandhi changed the title DLPX-85142 Revert "DLPX-85006 CVE-2022-48303 found in virtualization affected package tar_1.30+dfsg-7ubuntu0.20.04.2 (#277)" DLPX-85142 Unpin tar from linux-pkg on 6.0/stage Mar 13, 2023
@palash-gandhi
Copy link
Contributor Author

We can do it this way, or we can preserve the misc-debs package, and just remove the tar package from it.. i.e. so it'd be empty.. the idea being, the "infrastructure" will be there if we need to do this in the future..

Do we have thoughts if it'd be useful to keep the package definition around, for potential future use? or remove it, and if needed later, it can be resurrected (like I did)?

I think it makes sense to leave the infra behind.

@prakashsurya
Copy link
Contributor

I think it makes sense to leave the infra behind.

Let's verify that actually works, since I never tested it, with git-ab-pre-push -b misc-debs

@palash-gandhi palash-gandhi force-pushed the dlpx/pr/pgandhi-delphix/df5b5c77-4713-45a0-9a1d-f733be0d080d branch from 374cc3e to ed8535e Compare March 15, 2023 18:37
@palash-gandhi palash-gandhi merged commit 66cc1ec into 6.0/stage Mar 16, 2023
@palash-gandhi palash-gandhi deleted the dlpx/pr/pgandhi-delphix/df5b5c77-4713-45a0-9a1d-f733be0d080d branch March 16, 2023 15:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Development

Successfully merging this pull request may close these issues.

3 participants