Skip to content

chore(CR-36677): update version of docker to v29.4.0, update node_exporter to 1.11.0#122

Merged
vitalii-codefresh merged 1 commit intomasterfrom
CR-36677-security
Apr 9, 2026
Merged

chore(CR-36677): update version of docker to v29.4.0, update node_exporter to 1.11.0#122
vitalii-codefresh merged 1 commit intomasterfrom
CR-36677-security

Conversation

@vitalii-codefresh
Copy link
Copy Markdown
Contributor

@vitalii-codefresh vitalii-codefresh commented Apr 8, 2026

What

Fixes: https://codefresh-io.atlassian.net/browse/CR-36677

Why

Notes

Labels

Assign the following labels to the PR:

security - to trigger image scanning in CI build

PR Comments

Add the following comments to the PR:

/e2e - to trigger E2E build

Security Report

Important

Current summary is in beta mode.
Please analyze the full scan report for comprehensive details.

Fixed CVEs: 28

🟣 Critical: 3

  • CVE-2025-68121 in crypto/tls@1.25.6 at /usr/local/bin/containerd
  • CVE-2025-68121 in crypto/tls@1.24.12 at /bin/node_exporter
  • CVE-2025-68121 in crypto/tls@1.24.11 at /usr/local/libexec/docker/cli-plugins/docker-compose

🔴 High: 2

  • CVE-2025-66564 in github.com/sigstore/timestamp-authority/v2@v2.0.2 at /usr/local/bin/dockerd
  • CVE-2025-61726 in net/url@1.24.11 at /usr/local/libexec/docker/cli-plugins/docker-compose

🟠 Medium: 12

  • GHSA-xmrv-pmrh-hhx2 in github.com/aws/aws-sdk-go-v2/service/cloudwatchlogs@v1.63.1 at /usr/local/bin/dockerd
  • GHSA-xmrv-pmrh-hhx2 in github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream@v1.7.4 at /usr/local/bin/dockerd
  • CVE-2026-23992 in github.com/theupdateframework/go-tuf/v2@v2.3.0 at /usr/local/bin/dockerd
  • CVE-2026-23991 in github.com/theupdateframework/go-tuf/v2@v2.3.0 at /usr/local/bin/dockerd
  • CVE-2026-32778 in expat@2.7.4-r0 at unknown path
  • CVE-2026-32777 in expat@2.7.4-r0 at unknown path
  • CVE-2026-32776 in expat@2.7.4-r0 at unknown path
  • CVE-2026-27171 in zlib@1.3.1-r2 at unknown path
  • CVE-2026-24117 in github.com/sigstore/rekor@v1.4.3 at /usr/local/libexec/docker/cli-plugins/docker-buildx
  • CVE-2026-23831 in github.com/sigstore/rekor@v1.4.3 at /usr/local/libexec/docker/cli-plugins/docker-buildx
  • CVE-2025-61730 in crypto/tls@1.24.11 at /usr/local/libexec/docker/cli-plugins/docker-compose
  • CVE-2026-24686 in github.com/theupdateframework/go-tuf/v2@v2.3.0 at /usr/local/bin/dockerd

🟡 Low: 1

  • CVE-2026-1229 in github.com/cloudflare/circl@v1.6.1 at /usr/local/bin/dockerd

⚫ Unassigned: 10

@vitalii-codefresh vitalii-codefresh changed the title chore(CR-36677): update version of docker to v29.4.0 chore(CR-36677): update version of docker to v29.4.0, update node_exporter to 1.11.0 Apr 8, 2026
@vitalii-codefresh
Copy link
Copy Markdown
Contributor Author

/e2e

Copy link
Copy Markdown
Contributor

@masontikhonov masontikhonov left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Don't forget to open corrssponding PR to rootless branch.

@@ -1,5 +1,5 @@
# CI relies on this ARG. Don't remove or rename it
ARG DOCKER_VERSION=29.2.0
ARG DOCKER_VERSION=29.4.0
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I see release notes are not published yet. Let's wait for an official release before upgrade.

@masontikhonov masontikhonov changed the title chore(CR-36677): update version of docker to v29.4.0, update node_exporter to 1.11.0 chore: update version of docker to v29.4.0, update node_exporter to 1.11.0 Apr 8, 2026
@masontikhonov
Copy link
Copy Markdown
Contributor

@vitalii-codefresh I moved Jira number from git commit scope to PR description. Scope is not intended to keep ticket numbers, rather the scope of the code affected by changes.

@vitalii-codefresh vitalii-codefresh changed the title chore: update version of docker to v29.4.0, update node_exporter to 1.11.0 chore(CR-36677): update version of docker to v29.4.0, update node_exporter to 1.11.0 Apr 9, 2026
@vitalii-codefresh vitalii-codefresh merged commit bece2d5 into master Apr 9, 2026
8 checks passed
@vitalii-codefresh vitalii-codefresh deleted the CR-36677-security branch April 9, 2026 10:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants