Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

feat: update versions, set defaults to puppet8 #64

Merged
merged 1 commit into from
Sep 13, 2024
Merged

feat: update versions, set defaults to puppet8 #64

merged 1 commit into from
Sep 13, 2024

Conversation

rwaffen
Copy link
Member

@rwaffen rwaffen commented Sep 13, 2024

No description provided.

Signed-off-by: Robert Waffen <rw@betadots.de>
@rwaffen rwaffen requested a review from a team as a code owner September 13, 2024 07:22
Copy link

github-actions bot commented Sep 13, 2024

Outdated

Overview

Image reference ghcr.io/betadots/pdc:latest-7 ci/pdc:7
- digest 908582d4b0ff d1985bddee0e
- tag latest-7 7
- vulnerabilities critical: 2 high: 7 medium: 32 low: 14 unspecified: 2 critical: 2 high: 7 medium: 28 low: 14 unspecified: 2
- platform linux/amd64 linux/amd64
- size 311 MB 346 MB (+35 MB)
- packages 782 798 (+16)
Base Image ubuntu:22.04
also known as:
jammy
jammy-20240808
ubuntu:22.04
also known as:
jammy
jammy-20240808
- vulnerabilities critical: 0 high: 0 medium: 4 low: 12 critical: 0 high: 0 medium: 4 low: 12
Environment Variables (3 changes)
  • ± 3 changed
  • 12 unchanged
 BOLT_DISABLE_ANALYTICS=true
 BOLT_VERSION=3.30.0
 DEBIAN_FRONTEND=noninteractive
 LANG=en_US.UTF-8
 LANGUAGE=en_US:en
 LC_ALL=en_US.UTF-8
 PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/opt/puppetlabs/puppet/bin:/opt/puppetlabs/bin
 PDK_DISABLE_ANALYTICS=true
-PDK_VERSION=3.2.0.1
+PDK_VERSION=3.3.0.0
 PUPPETDB_TERMINI_VERSION=7.19.1
 PUPPET_DEB=puppet7-release-jammy.deb
 PUPPET_RELEASE=7
 PUPPET_TOOLS_DEB=puppet-tools-release-jammy.deb
-PUPPET_VERSION=7.32.1
+PUPPET_VERSION=7.33.0
-TERRAFORM_VERSION=1.9.3
+TERRAFORM_VERSION=1.9.5
Packages and Vulnerabilities (65 package changes and 2 vulnerability changes)
  • ➖ 1 packages removed
  • ♾️ 64 packages changed
  • 590 packages unchanged
  • ✔️ 2 vulnerabilities removed
Changes for packages of type deb (9 changes)
Package Version
ghcr.io/betadots/pdc:latest-7
Version
ci/pdc:7
♾️ apt 2.4.12 2.4.13
♾️ base-files 12ubuntu4.6 12ubuntu4.7
♾️ libapt-pkg6.0 2.4.12 2.4.13
♾️ libssl3 3.0.2-0ubuntu1.17 3.0.2-0ubuntu1.18
♾️ openssl 3.0.2-0ubuntu1.17 3.0.2-0ubuntu1.18
critical: 0 high: 0 medium: 2 low: 0 critical: 0 high: 0 medium: 1 low: 0
Removed vulnerabilities (1):
  • medium : CVE--2024--6119
♾️ pdk 3.2.0.1-1jammy 3.3.0.0-1jammy
♾️ puppet-agent 7.32.1-1jammy 7.33.0-1jammy
♾️ python3-pkg-resources 59.6.0-1.2ubuntu0.22.04.1 59.6.0-1.2ubuntu0.22.04.2
♾️ setuptools 59.6.0-1.2ubuntu0.22.04.1 59.6.0-1.2ubuntu0.22.04.2
Changes for packages of type gem (55 changes)
Package Version
ghcr.io/betadots/pdc:latest-7
Version
ci/pdc:7
♾️ addressable 2.8.6 2.8.7
♾️ aws-partitions 1.927.0 1.972.0
♾️ aws-sdk-core 3.195.0 3.203.0
♾️ aws-sdk-ec2 1.456.0 1.472.0
♾️ aws-sigv4 1.8.0 1.9.1
♾️ builder 3.2.4 3.3.0
♾️ childprocess 4.1.0 5.0.0
♾️ concurrent-ruby 1.2.3 1.3.4
♾️ cri 2.15.11 2.15.12
♾️ docile 1.4.0 1.4.1
♾️ docker-api 2.2.0 2.3.0
♾️ erubi 1.12.0 1.13.0
♾️ excon 0.110.0 0.111.0
♾️ facter 4.8.0 4.9.0
♾️ facterdb 1.24.0 2.1.0
♾️ faraday 2.9.0 1.10.3
faraday-follow_redirects 0.3.0
♾️ faraday-net_http 3.1.0 1.0.2
♾️ fast_gettext 2.3.0 3.1.0
♾️ ffi 1.16.3 1.17.0
♾️ getoptlong 0.2.0 0.2.1
♾️ highline 3.0.1 3.1.1
♾️ io-console 0.6.0 0.7.2
♾️ json-schema 4.3.0 5.0.0
♾️ logging 2.3.1 2.4.0
♾️ metadata-json-lint 4.0.0 4.1.0
♾️ mocha 1.16.1 2.4.5
♾️ net-http-persistent 4.0.2 4.0.4
♾️ nori 2.7.0 2.7.1
♾️ parallel 1.24.0 1.26.3
♾️ parser 3.3.1.0 3.3.5.0
♾️ pdk 3.2.0 3.3.0
♾️ public_suffix 5.0.5 6.0.1
♾️ puppet 8.6.0 8.8.1
♾️ puppet-strings 4.1.2 4.1.3
♾️ puppet_forge 5.0.3 3.2.0
♾️ puppet_litmus 1.4.0 1.5.0
♾️ puppetlabs_spec_helper 7.2.0 7.4.0
♾️ r10k 3.16.0 3.16.2
♾️ racc 1.7.3 1.8.1
♾️ rdoc 6.5.0 6.5.1.1
critical: 0 high: 0 medium: 1 low: 0
Removed vulnerabilities (1):
  • medium : CVE--2024--27281
♾️ regexp_parser 2.9.1 2.9.2
♾️ reline 0.3.2 0.5.10
♾️ rexml 3.2.6 3.3.6
critical: 0 high: 0 medium: 5 low: 0
Removed vulnerabilities (5):
  • medium : CVE--2024--41946
  • medium : CVE--2024--41123
  • medium : CVE--2024--43398
  • medium : CVE--2024--35176
  • medium : CVE--2024--39908
♾️ rspec-core 3.13.0 3.13.1
♾️ rspec-expectations 3.13.0 3.13.3
♾️ rspec-puppet 4.0.2 5.0.0
♾️ rspec-puppet-facts 3.0.0 4.0.0
♾️ rubocop-ast 1.31.3 1.32.3
♾️ rubocop-capybara 2.20.0 2.21.0
♾️ rubyntlm 0.6.3 0.6.5
♾️ simplecov-html 0.12.3 0.13.1
♾️ specinfra 2.89.0 2.90.1
♾️ uri 0.13.0 0.12.2
♾️ winrm 2.3.6 2.3.9
Changes for packages of type golang (1 changes)
Package Version
ghcr.io/betadots/pdc:latest-7
Version
ci/pdc:7
♾️ github.com/hashicorp/go-tfe 1.51.0 1.58.0

Copy link

Overview

Image reference ghcr.io/betadots/pdc:latest-8 ci/pdc:8
- digest 2481f4f37641 22b393447934
- tag latest-8 8
- vulnerabilities critical: 2 high: 7 medium: 31 low: 14 unspecified: 1 critical: 2 high: 7 medium: 27 low: 14 unspecified: 1
- platform linux/amd64 linux/amd64
- size 315 MB 351 MB (+36 MB)
- packages 783 799 (+16)
Base Image ubuntu:22.04
also known as:
jammy
jammy-20240808
ubuntu:22.04
also known as:
jammy
jammy-20240808
- vulnerabilities critical: 0 high: 0 medium: 4 low: 12 critical: 0 high: 0 medium: 4 low: 12
Environment Variables (3 changes)
  • ± 3 changed
  • 12 unchanged
 BOLT_DISABLE_ANALYTICS=true
 BOLT_VERSION=3.30.0
 DEBIAN_FRONTEND=noninteractive
 LANG=en_US.UTF-8
 LANGUAGE=en_US:en
 LC_ALL=en_US.UTF-8
 PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/opt/puppetlabs/puppet/bin:/opt/puppetlabs/bin
 PDK_DISABLE_ANALYTICS=true
-PDK_VERSION=3.2.0.1
+PDK_VERSION=3.3.0.0
 PUPPETDB_TERMINI_VERSION=8.7.0
 PUPPET_DEB=puppet8-release-jammy.deb
 PUPPET_RELEASE=8
 PUPPET_TOOLS_DEB=puppet-tools-release-jammy.deb
-PUPPET_VERSION=8.8.1
+PUPPET_VERSION=8.9.0
-TERRAFORM_VERSION=1.9.3
+TERRAFORM_VERSION=1.9.5
Packages and Vulnerabilities (64 package changes and 2 vulnerability changes)
  • ➖ 1 packages removed
  • ♾️ 63 packages changed
  • 591 packages unchanged
  • ✔️ 2 vulnerabilities removed
Changes for packages of type deb (9 changes)
Package Version
ghcr.io/betadots/pdc:latest-8
Version
ci/pdc:8
♾️ apt 2.4.12 2.4.13
♾️ base-files 12ubuntu4.6 12ubuntu4.7
♾️ libapt-pkg6.0 2.4.12 2.4.13
♾️ libssl3 3.0.2-0ubuntu1.17 3.0.2-0ubuntu1.18
♾️ openssl 3.0.2-0ubuntu1.17 3.0.2-0ubuntu1.18
critical: 0 high: 0 medium: 2 low: 0 critical: 0 high: 0 medium: 1 low: 0
Removed vulnerabilities (1):
  • medium : CVE--2024--6119
♾️ pdk 3.2.0.1-1jammy 3.3.0.0-1jammy
♾️ puppet-agent 8.8.1-1jammy 8.9.0-1jammy
♾️ python3-pkg-resources 59.6.0-1.2ubuntu0.22.04.1 59.6.0-1.2ubuntu0.22.04.2
♾️ setuptools 59.6.0-1.2ubuntu0.22.04.1 59.6.0-1.2ubuntu0.22.04.2
Changes for packages of type gem (54 changes)
Package Version
ghcr.io/betadots/pdc:latest-8
Version
ci/pdc:8
♾️ addressable 2.8.6 2.8.7
♾️ aws-partitions 1.927.0 1.972.0
♾️ aws-sdk-core 3.195.0 3.203.0
♾️ aws-sdk-ec2 1.456.0 1.472.0
♾️ aws-sigv4 1.8.0 1.9.1
♾️ builder 3.2.4 3.3.0
♾️ childprocess 4.1.0 5.0.0
♾️ concurrent-ruby 1.2.3 1.3.4
♾️ cri 2.15.11 2.15.12
♾️ docile 1.4.0 1.4.1
♾️ docker-api 2.2.0 2.3.0
♾️ erubi 1.12.0 1.13.0
♾️ excon 0.110.0 0.111.0
♾️ facter 4.8.0 4.9.0
♾️ facterdb 1.24.0 2.1.0
♾️ faraday 2.9.0 1.10.3
faraday-follow_redirects 0.3.0
♾️ faraday-net_http 3.1.0 1.0.2
♾️ fast_gettext 2.3.0 3.1.0
♾️ ffi 1.16.3 1.17.0
♾️ getoptlong 0.2.0 0.2.1
♾️ highline 3.0.1 3.1.1
♾️ io-console 0.6.0 0.7.2
♾️ json-schema 4.3.0 5.0.0
♾️ logging 2.3.1 2.4.0
♾️ metadata-json-lint 4.0.0 4.1.0
♾️ mocha 1.16.1 2.4.5
♾️ net-http-persistent 4.0.2 4.0.4
♾️ nori 2.7.0 2.7.1
♾️ parallel 1.24.0 1.26.3
♾️ parser 3.3.1.0 3.3.5.0
♾️ pdk 3.2.0 3.3.0
♾️ public_suffix 5.0.5 6.0.1
♾️ puppet 8.8.1 8.9.0
♾️ puppet-strings 4.1.2 4.1.3
♾️ puppet_forge 5.0.3 3.2.0
♾️ puppet_litmus 1.4.0 1.5.0
♾️ puppetlabs_spec_helper 7.2.0 7.4.0
♾️ r10k 3.16.0 3.16.2
♾️ racc 1.7.3 1.8.1
♾️ regexp_parser 2.9.1 2.9.2
♾️ reline 0.3.2 0.5.10
♾️ rexml 3.2.6 3.3.6
critical: 0 high: 0 medium: 5 low: 0
Removed vulnerabilities (5):
  • medium : CVE--2024--41946
  • medium : CVE--2024--41123
  • medium : CVE--2024--43398
  • medium : CVE--2024--35176
  • medium : CVE--2024--39908
♾️ rspec-core 3.13.0 3.13.1
♾️ rspec-expectations 3.13.0 3.13.3
♾️ rspec-puppet 4.0.2 5.0.0
♾️ rspec-puppet-facts 3.0.0 4.0.0
♾️ rubocop-ast 1.31.3 1.32.3
♾️ rubocop-capybara 2.20.0 2.21.0
♾️ rubyntlm 0.6.3 0.6.5
♾️ simplecov-html 0.12.3 0.13.1
♾️ specinfra 2.89.0 2.90.1
♾️ uri 0.13.0 0.12.2
♾️ winrm 2.3.6 2.3.9
Changes for packages of type golang (1 changes)
Package Version
ghcr.io/betadots/pdc:latest-8
Version
ci/pdc:8
♾️ github.com/hashicorp/go-tfe 1.51.0 1.58.0

@github-advanced-security
Copy link

This pull request sets up GitHub code scanning for this repository. Once the scans have completed and the checks have passed, the analysis results for this pull request branch will appear on this overview. Once you merge this pull request, the 'Security' tab will show more code scanning analysis results (for example, for the default branch). Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results. For more information about GitHub code scanning, check out the documentation.

Copy link
Member

@bastelfreak bastelfreak left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

looks good to me, but should we do this as a major release?

@rwaffen rwaffen merged commit ab16d08 into main Sep 13, 2024
7 checks passed
@rwaffen rwaffen deleted the updates branch September 13, 2024 07:27
@rwaffen
Copy link
Member Author

rwaffen commented Sep 13, 2024

no not really, the "defaults" i change, are only build default, if no variables from the json are available. I set these to test local builds without the json.

but no hard feelings, can also do a major ¯\_(ツ)_/¯

@bastelfreak
Copy link
Member

ah right, true. And I assume people usually don't just run docker build for pdc but use your containers, so that would be fine as a minor release.

@rwaffen rwaffen added the enhancement New feature or request label Sep 13, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants