Skip to content

chore(CR-36677): update version of docker to v29.4.0, update node_exporter to 1.11.0#125

Merged
vitalii-codefresh merged 2 commits intorootlessfrom
CR-36677-security-rootless
Apr 9, 2026
Merged

chore(CR-36677): update version of docker to v29.4.0, update node_exporter to 1.11.0#125
vitalii-codefresh merged 2 commits intorootlessfrom
CR-36677-security-rootless

Conversation

@vitalii-codefresh
Copy link
Copy Markdown
Contributor

@vitalii-codefresh vitalii-codefresh commented Apr 9, 2026

What

Why

Notes

Labels

Assign the following labels to the PR:

security - to trigger image scanning in CI build

PR Comments

Add the following comments to the PR:

/e2e - to trigger E2E build

Security Report

Important

Current summary is in beta mode.
Please analyze the full scan report for comprehensive details.

Fixed CVEs: 23

🟣 Critical: 3

  • CVE-2025-68121 in crypto/tls@1.25.6 at /usr/local/bin/containerd
  • CVE-2025-68121 in crypto/tls@1.24.12 at /bin/node_exporter
  • CVE-2025-68121 in crypto/tls@1.24.11 at /usr/local/libexec/docker/cli-plugins/docker-compose

🔴 High: 2

  • CVE-2025-66564 in github.com/sigstore/timestamp-authority/v2@v2.0.2 at /usr/local/bin/dockerd
  • CVE-2025-61726 in net/url@1.24.11 at /usr/local/libexec/docker/cli-plugins/docker-compose

🟠 Medium: 8

  • GHSA-xmrv-pmrh-hhx2 in github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream@v1.7.4 at /usr/local/bin/dockerd
  • GHSA-xmrv-pmrh-hhx2 in github.com/aws/aws-sdk-go-v2/service/cloudwatchlogs@v1.63.1 at /usr/local/bin/dockerd
  • CVE-2026-23992 in github.com/theupdateframework/go-tuf/v2@v2.3.0 at /usr/local/bin/dockerd
  • CVE-2026-23991 in github.com/theupdateframework/go-tuf/v2@v2.3.0 at /usr/local/bin/dockerd
  • CVE-2026-24117 in github.com/sigstore/rekor@v1.4.3 at /usr/local/libexec/docker/cli-plugins/docker-buildx
  • CVE-2026-23831 in github.com/sigstore/rekor@v1.4.3 at /usr/local/libexec/docker/cli-plugins/docker-buildx
  • CVE-2025-61730 in crypto/tls@1.24.11 at /usr/local/libexec/docker/cli-plugins/docker-compose
  • CVE-2026-24686 in github.com/theupdateframework/go-tuf/v2@v2.3.0 at /usr/local/bin/dockerd

🟡 Low: 1

  • CVE-2026-1229 in github.com/cloudflare/circl@v1.6.1 at /usr/local/bin/dockerd

⚫ Unassigned: 9

@vitalii-codefresh
Copy link
Copy Markdown
Contributor Author

/e2e

@vitalii-codefresh vitalii-codefresh merged commit 4c088c0 into rootless Apr 9, 2026
4 checks passed
@vitalii-codefresh vitalii-codefresh deleted the CR-36677-security-rootless branch April 9, 2026 10:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants