Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Tracking issue for releases v1.9.3 and v1.8.4 #10502

Closed
4 tasks done
rikatz opened this issue Oct 11, 2023 · 19 comments
Closed
4 tasks done

Tracking issue for releases v1.9.3 and v1.8.4 #10502

rikatz opened this issue Oct 11, 2023 · 19 comments
Assignees
Labels
kind/bug Categorizes issue or PR as related to a bug. priority/critical-urgent Highest priority. Must be actively worked on as someone's top priority right now. triage/accepted Indicates an issue or PR is ready to be actively worked on.

Comments

@rikatz
Copy link
Contributor

rikatz commented Oct 11, 2023

We need new releases due to:

/priority urgent
/kind bug
/triage accepted

Tasks

Preview Give feedback
@k8s-ci-robot k8s-ci-robot added kind/bug Categorizes issue or PR as related to a bug. triage/accepted Indicates an issue or PR is ready to be actively worked on. labels Oct 11, 2023
@k8s-ci-robot
Copy link
Contributor

@rikatz: The label(s) priority/urgent cannot be applied, because the repository doesn't have them.

In response to this:

We need new releases due to:

  • New curl release (upcoming CVE)
  • New Go release (CVE-2023-44487 and CVE-2023-39325)
  • Patched NGINX - Thanks @Hacks4Snacks for quickly adding the patch on NGINX compilation

/priority urgent
/kind bug
/triage accepted

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository.

@tao12345666333 tao12345666333 added the priority/critical-urgent Highest priority. Must be actively worked on as someone's top priority right now. label Oct 11, 2023
@rikatz
Copy link
Contributor Author

rikatz commented Oct 11, 2023

#10503

@strongjz strongjz self-assigned this Oct 11, 2023
@strongjz strongjz moved this to In Progress in [SIG Network] Ingress NGINX Oct 11, 2023
@strongjz
Copy link
Member

open kubernetes/k8s.io#5962 for nginx and test runner

@strongjz
Copy link
Member

update all the images now that they have been promoted #10506

@strongjz
Copy link
Member

1.8 cherry pick #10508

1.9 cherry pick #10507

@rikatz
Copy link
Contributor Author

rikatz commented Oct 11, 2023

Release 1.8.3 will be stuck with the fact that we've removed AJP module from build. We need to think on a way to get around it now :/

@rikatz
Copy link
Contributor Author

rikatz commented Oct 11, 2023

#10509 for 1.8. I'm closing the original cherry-pick

@rikatz
Copy link
Contributor Author

rikatz commented Oct 12, 2023

kubernetes/k8s.io#5965 for image promotion

@chris-ng-scmp
Copy link

Hi, how about 1.7? Is it still a supported version, or the CVEs are not affecting 1.7?

Many thanks

@rikatz
Copy link
Contributor Author

rikatz commented Oct 12, 2023

1.7 is not supported anymore

@rikatz
Copy link
Contributor Author

rikatz commented Oct 12, 2023

Update of release status: it is 1am here, @tao12345666333 is taking over now on manifests, chart and other stuff generation for v1.8 and v1.9

I need soon to fix mage again (sorry @strongjz I keep breaking stuff)

@vinay01tech
Copy link

@rikatz Where I can find release cycle, to make sure we are up-to-date ?

@rikatz
Copy link
Contributor Author

rikatz commented Oct 12, 2023

Required new PRs to bump go/x/net (forgot to cherry pick it, sorry....)
#10515
#10517

Once merged, we will post trivy and grype results here

@rikatz
Copy link
Contributor Author

rikatz commented Oct 12, 2023

Release will be a bit delayed due to problems with release script and me forgetting the bump of x/net, I will work on it during my afternoon

@strongjz
Copy link
Member

There was also an issue with 1.8 release since we deprecated AJP in 1.9, so the back port to 1.8 for the CVE fix break CI. @rikatz as always did great work and fixed it. We should have both 1.8.4 and 1.9.3 out today.

@strongjz
Copy link
Member

promotion job kubernetes/k8s.io#5968

@strongjz
Copy link
Member

1.9.3 #10520

1.8.4 #10519

@strongjz strongjz changed the title Tracking issue for releases v1.9.2 and v1.8.3 Tracking issue for releases v1.9.3 and v1.8.4 Oct 12, 2023
@strongjz
Copy link
Member

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
kind/bug Categorizes issue or PR as related to a bug. priority/critical-urgent Highest priority. Must be actively worked on as someone's top priority right now. triage/accepted Indicates an issue or PR is ready to be actively worked on.
Projects
Archived in project
Development

No branches or pull requests

6 participants