[Project Darkstar] PSHP-673: Remediate CVE-2026-45447 in managed-upgrade-operator#683
Conversation
…bi9/ubi-minimal to 9.8-1784092902 Addresses CVE-2026-45447 (Important, CVSS 8.1). Update UBI9 minimal base image to include openssl-libs >= 1:3.5.5-4.el9_8. Ref: PSHP-673 Project Darkstar — automated CVE remediation (contact: Kevin Seiter) Co-Authored-By: Claude Code <noreply@anthropic.com>
|
@kseiter-rh: This pull request references PSHP-673 which is a valid jira issue. Warning: The referenced jira issue has an invalid target version for the target branch this PR targets: expected the vulnerability to target the "5.0.0" version, but no target version was set. DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. |
|
Important Review skippedReview was skipped due to path filters ⛔ Files ignored due to path filters (2)
CodeRabbit blocks several paths by default. You can override this behavior by explicitly including those paths in the path filters. For example, including ⚙️ Run configurationConfiguration used: Repository YAML (base), Central YAML (inherited) Review profile: CHILL Plan: Enterprise Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Skipping CI for Draft Pull Request. |
|
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: kseiter-rh The full list of commands accepted by this bot can be found here. DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
|
/test all |
|
PR needs rebase. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
Project Darkstar — Automated CVE Remediation
Summary
CVE Details
Unfixable CVEs (no upstream fix available)
Changes
build/Dockerfile: UBI9 minimal 9.8-1782797275 -> 9.8-1784092902build/Dockerfile.olm-registry: UBI9 minimal 9.8-1782797275 -> 9.8-1784092902Verification
References
Project Darkstar — Automated CVE Remediation | Contact: Kevin Seiter (ROSA Trust Engineering)
About Project Darkstar