-
Notifications
You must be signed in to change notification settings - Fork 26
DNM: 2026.1 test check review #2499
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Draft
Alex-Welsh
wants to merge
7
commits into
stackhpc/2026.1
Choose a base branch
from
2026.1-check-review
base: stackhpc/2026.1
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Draft
Changes from all commits
Commits
Show all changes
7 commits
Select commit
Hold shift + click to select a range
cfd340c
Bump pulp-repo-versions.yml to latest
Alex-Welsh 9f5b17a
Set build_only in kolla repos
Alex-Welsh 3e2a164
Add more vulnerability skips
Alex-Welsh b4d357d
2026.1 full container rebuild
Alex-Welsh fce974b
Bump pulp container to 3.85.26
Alex-Welsh 6ef92b2
Switch to Canonical Squid 7.2 image
Alex-Welsh 6b87871
Add new IPA images for 2026.1
Alex-Welsh File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -1,8 +1,6 @@ | ||
| --- | ||
| # IPA image versioning tags | ||
| #TODO: Switch once RL10 images are available | ||
| stackhpc_rocky_9_ipa_image_version: "2025.1-20260420T095100" | ||
| stackhpc_rocky_9_ipa_image_version_aarch64: "2025.1-20260420T095100" | ||
| stackhpc_rocky_10_ipa_image_version: "2025.1-20260805T091024" | ||
| stackhpc_rocky_10_ipa_image_version_aarch64: "2025.1-20260805T091024" | ||
| stackhpc_rocky_10_ipa_image_version: "2026.1-20260813T115725" | ||
| stackhpc_rocky_10_ipa_image_version_aarch64: "2026.1-20260813T115725" | ||
| stackhpc_ubuntu_noble_ipa_image_version: "2025.1-20260420T095100" |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -1,49 +1,49 @@ | ||
| --- | ||
| # This file is autogenerated by Ansible using the following workflow: | ||
| # https://github.com/stackhpc/stackhpc-release-train/actions/workflows/package-update-kayobe.yml | ||
| stackhpc_pulp_repo_almalinux_10_proxysql_3_0_version: 20260605T211649 | ||
| stackhpc_pulp_repo_centos_stream_10_docker_aarch64_version: 20260620T010620 | ||
| stackhpc_pulp_repo_centos_stream_10_docker_version: 20260619T215327 | ||
| stackhpc_pulp_repo_centos_stream_10_nfv_openvswitch_aarch64_version: 20260603T233007 | ||
| stackhpc_pulp_repo_centos_stream_10_nfv_openvswitch_version: 20260602T230909 | ||
| stackhpc_pulp_repo_centos_stream_10_storage_ceph_squid_aarch64_version: 20260603T233007 | ||
| stackhpc_pulp_repo_centos_stream_10_storage_ceph_squid_version: 20260602T230909 | ||
| stackhpc_pulp_repo_doca_3_2_2_rhel10_aarch64_version: 20260326T091359 | ||
| stackhpc_pulp_repo_doca_3_2_2_rhel10_x86_64_version: 20260326T091359 | ||
| stackhpc_pulp_repo_docker_ce_ubuntu_noble_version: 20260622T222357 | ||
| stackhpc_pulp_repo_elrepo_10_aarch64_version: 20260220T152827 | ||
| stackhpc_pulp_repo_elrepo_10_version: 20260620T002710 | ||
| stackhpc_pulp_repo_epel_10_aarch64_version: 20260624T000231 | ||
| stackhpc_pulp_repo_epel_10_version: 20260623T220913 | ||
| stackhpc_pulp_repo_ubuntu_noble_fluent_6_version: 20260615T110539 | ||
| stackhpc_pulp_repo_rhel_10_fluent_6_version: 20260327T202539 | ||
| stackhpc_pulp_repo_grafana_version: 20260623T210745 | ||
| stackhpc_pulp_repo_almalinux_10_proxysql_3_0_version: 20260804T131930 | ||
| stackhpc_pulp_repo_centos_stream_10_docker_aarch64_version: 20260804T131930 | ||
| stackhpc_pulp_repo_centos_stream_10_docker_version: 20260804T131930 | ||
| stackhpc_pulp_repo_centos_stream_10_nfv_openvswitch_aarch64_version: 20260804T131930 | ||
| stackhpc_pulp_repo_centos_stream_10_nfv_openvswitch_version: 20260804T131930 | ||
| stackhpc_pulp_repo_centos_stream_10_storage_ceph_squid_aarch64_version: 20260804T131930 | ||
| stackhpc_pulp_repo_centos_stream_10_storage_ceph_squid_version: 20260804T131930 | ||
| stackhpc_pulp_repo_doca_3_2_2_rhel10_aarch64_version: 20260804T131930 | ||
| stackhpc_pulp_repo_doca_3_2_2_rhel10_x86_64_version: 20260804T131930 | ||
| stackhpc_pulp_repo_docker_ce_ubuntu_noble_version: 20260804T131930 | ||
| stackhpc_pulp_repo_elrepo_10_aarch64_version: 20260804T131930 | ||
| stackhpc_pulp_repo_elrepo_10_version: 20260804T131930 | ||
| stackhpc_pulp_repo_epel_10_aarch64_version: 20260804T131930 | ||
| stackhpc_pulp_repo_epel_10_version: 20260804T131930 | ||
| stackhpc_pulp_repo_grafana_apt_version: 20260622T222446 | ||
| stackhpc_pulp_repo_grafana_version: 20260804T131930 | ||
| stackhpc_pulp_repo_opensearch_3_x_yum_version: 20260610T213138 | ||
| stackhpc_pulp_repo_opensearch_dashboards_3_x_yum_version: 20260610T213138 | ||
| stackhpc_pulp_repo_rhel9_rabbitmq_erlang_27_aarch64_version: 20260112T224827 | ||
| stackhpc_pulp_repo_rhel9_rabbitmq_erlang_version: 20260616T214234 | ||
| stackhpc_pulp_repo_rhel9_rabbitmq_server_version: 20260616T214234 | ||
| stackhpc_pulp_repo_rhel_10_mariadb_11_4_aarch64_version: 20260527T210633 | ||
| stackhpc_pulp_repo_rhel_10_mariadb_11_4_version: 20260527T210633 | ||
| stackhpc_pulp_repo_rocky_10_2_appstream_aarch64_version: 20260620T010620 | ||
| stackhpc_pulp_repo_rocky_10_2_appstream_source_version: 20260620T003535 | ||
| stackhpc_pulp_repo_rocky_10_2_appstream_version: 20260620T002710 | ||
| stackhpc_pulp_repo_rocky_10_2_baseos_aarch64_version: 20260620T010620 | ||
| stackhpc_pulp_repo_rocky_10_2_baseos_source_version: 20260620T003535 | ||
| stackhpc_pulp_repo_rocky_10_2_baseos_version: 20260620T003803 | ||
| stackhpc_pulp_repo_rocky_10_2_crb_aarch64_version: 20260620T010620 | ||
| stackhpc_pulp_repo_rocky_10_2_crb_source_version: 20260602T004048 | ||
| stackhpc_pulp_repo_rocky_10_2_crb_version: 20260620T002710 | ||
| stackhpc_pulp_repo_rocky_10_2_extras_aarch64_version: 20260602T012631 | ||
| stackhpc_pulp_repo_rocky_10_2_extras_source_version: 20260602T004048 | ||
| stackhpc_pulp_repo_rocky_10_2_extras_version: 20260602T001113 | ||
| stackhpc_pulp_repo_rocky_10_2_highavailability_aarch64_version: 20260602T012631 | ||
| stackhpc_pulp_repo_rocky_10_2_highavailability_source_version: 20260602T004048 | ||
| stackhpc_pulp_repo_rocky_10_2_highavailability_version: 20260602T001113 | ||
| stackhpc_pulp_repo_rocky_10_2_security_aarch64_version: 20260606T230245 | ||
| stackhpc_pulp_repo_rocky_10_2_security_source_version: 20260605T232846 | ||
| stackhpc_pulp_repo_rocky_10_2_security_version: 20260606T223509 | ||
| stackhpc_pulp_repo_ubuntu_cloud_archive_version: 20260621T235438 | ||
| stackhpc_pulp_repo_ubuntu_noble_security_version: 20260622T030723 | ||
| stackhpc_pulp_repo_ubuntu_noble_version: 20260622T030723 | ||
| stackhpc_pulp_repo_rhel9_rabbitmq_erlang_27_aarch64_version: 20260804T131930 | ||
| stackhpc_pulp_repo_rhel9_rabbitmq_erlang_version: 20260804T131930 | ||
| stackhpc_pulp_repo_rhel9_rabbitmq_server_version: 20260804T131930 | ||
| stackhpc_pulp_repo_rhel_10_fluent_6_version: 20260804T131930 | ||
| stackhpc_pulp_repo_rhel_10_mariadb_11_4_aarch64_version: 20260804T131930 | ||
| stackhpc_pulp_repo_rhel_10_mariadb_11_4_version: 20260804T131930 | ||
| stackhpc_pulp_repo_rocky_10_2_appstream_aarch64_version: 20260804T131930 | ||
| stackhpc_pulp_repo_rocky_10_2_appstream_source_version: 20260804T131930 | ||
| stackhpc_pulp_repo_rocky_10_2_appstream_version: 20260804T131930 | ||
| stackhpc_pulp_repo_rocky_10_2_baseos_aarch64_version: 20260804T131930 | ||
| stackhpc_pulp_repo_rocky_10_2_baseos_source_version: 20260804T131930 | ||
| stackhpc_pulp_repo_rocky_10_2_baseos_version: 20260804T131930 | ||
| stackhpc_pulp_repo_rocky_10_2_crb_aarch64_version: 20260804T131930 | ||
| stackhpc_pulp_repo_rocky_10_2_crb_source_version: 20260804T131930 | ||
| stackhpc_pulp_repo_rocky_10_2_crb_version: 20260804T131930 | ||
| stackhpc_pulp_repo_rocky_10_2_extras_aarch64_version: 20260804T131930 | ||
| stackhpc_pulp_repo_rocky_10_2_extras_source_version: 20260804T131930 | ||
| stackhpc_pulp_repo_rocky_10_2_extras_version: 20260804T131930 | ||
| stackhpc_pulp_repo_rocky_10_2_highavailability_aarch64_version: 20260804T131930 | ||
| stackhpc_pulp_repo_rocky_10_2_highavailability_source_version: 20260804T131930 | ||
| stackhpc_pulp_repo_rocky_10_2_highavailability_version: 20260804T131930 | ||
| stackhpc_pulp_repo_rocky_10_2_security_aarch64_version: 20260804T131930 | ||
| stackhpc_pulp_repo_rocky_10_2_security_source_version: 20260804T131930 | ||
| stackhpc_pulp_repo_rocky_10_2_security_version: 20260804T131930 | ||
| stackhpc_pulp_repo_ubuntu_cloud_archive_version: 20260804T131930 | ||
| stackhpc_pulp_repo_ubuntu_noble_fluent_6_version: 20260615T110539 | ||
| stackhpc_pulp_repo_ubuntu_noble_security_version: 20260804T131930 | ||
| stackhpc_pulp_repo_ubuntu_noble_version: 20260804T131930 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
7 changes: 7 additions & 0 deletions
7
releasenotes/notes/ubuntu-squid-container-75698bf1b9535163.yaml
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,7 @@ | ||
| --- | ||
| features: | ||
| - | | ||
| The Squid proxy container has been switched from a StackHPC-maintained | ||
| custom image, to a public image maintained by Canonical. The version of | ||
| Squid is bumped from 6.10 to 7.2. The old image was based on Rocky Linux 10, | ||
| and the new one is based on Ubuntu 26.04. |
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🔒 Security & Privacy | 🟠 Major | 🏗️ Heavy lift
🧩 Analysis chain
🏁 Script executed:
Repository: stackhpc/stackhpc-kayobe-config
Length of output: 12702
🌐 Web query:
CVE-2026-59873 node-tar package affected versions fixed version💡 Result:
CVE-2026-59873 is a critical Denial of Service (DoS) vulnerability affecting the node-tar package [1][2]. Affected versions: All versions up to and including 7.5.18 [1][2]. Fixed version: 7.5.19 [1][3][2]. The vulnerability arises because the library fails to enforce hard upper bounds on total decompressed data, entry counts, or decompression ratios [3][4]. This allows an attacker to use a maliciously crafted "Gzip Bomb" to exhaust server resources, such as disk space and CPU, leading to potential service outages [1][2]. Users are advised to upgrade to version 7.5.19 or higher to mitigate this risk [1][3].
Citations:
🌐 Web query:
GHSA-r277-6w6q-xmqw getkin/kine-openapi affected versions fixed version💡 Result:
The security advisory GHSA-r277-6w6q-xmqw identifies a critical "fail-open" authentication bypass vulnerability in the getkin/kin-openapi Go library [1][2]. Affected versions: All versions before 0.144.0 [3]. Fixed version: 0.144.0 [3]. The vulnerability exists in the ValidationHandler.Load function, which incorrectly replaced a nil AuthenticationFunc with NoopAuthenticationFunc by default [1][4]. Because NoopAuthenticationFunc always returns nil, this caused OpenAPI security requirements (such as API keys or OAuth tokens) to be silently bypassed for unauthenticated requests [1][5]. The fix in version 0.144.0 ensures that a nil AuthenticationFunc is not automatically replaced with the no-op version, causing such requests to correctly return an error instead of passing validation [5]. Users who intentionally require no-op authentication must now explicitly set h.AuthenticationFunc = openapi3filter.NoopAuthenticationFunc [5].
Citations:
🌐 Web query:
GitHub advisories GHSA-r277-6w6q-xmqw grafana affected packages node-tar GitHub advisories💡 Result:
The GitHub advisory GHSA-r277-6w6q-xmqw identifies a critical-severity authentication bypass vulnerability in the Go package getkin/kin-openapi [1][2]. It is not directly related to node-tar; rather, it pertains to the ValidationHandler.Load method in kin-openapi, which incorrectly defaults to a NoopAuthenticationFunc when a nil AuthenticationFunc is provided, effectively disabling security checks for API requests [1]. While your query associated this advisory with Grafana and node-tar, the connection is as follows: - Grafana: The getkin/kin-openapi package is a dependency used within Grafana [3]. Consequently, Grafana instances may be affected by this vulnerability through that dependency [3]. - node-tar: There is no direct link between GHSA-r277-6w6q-xmqw and node-tar. The node-tar library has its own distinct set of security advisories (e.g., GHSA-8qq5-rm4j-mr97, GHSA-83g3-92jg-28cx, and GHSA-9ppj-qmqm-q256) regarding file system traversal and arbitrary file write vulnerabilities [4][5][6]. Users should review their dependencies to ensure they are using patched versions of getkin/kin-openapi and, separately, ensure node-tar is updated to a secure version to address its specific, unrelated vulnerabilities [4][5][6].
Citations:
🌐 Web query:
GitHub advisories CVE-2026-59873 node-tar GitHub advisories💡 Result:
CVE-2026-59873 is a critical security vulnerability in the node-tar library (npm package tar) that involves a Denial of Service (DoS) condition caused by unlimited input processing [1][2][3]. Key details of the advisory: - Vulnerability Type: Decompression/parse DoS via unlimited input [1][2]. - Description: The node-tar library does not enforce hard upper bounds on total decompressed data, entry counts, or decompression ratios during archive extraction [1][4]. An attacker can exploit this by providing a maliciously crafted archive—often referred to as a "Gzip Bomb"—that causes the library to consume excessive disk space and CPU resources until the host service crashes or exhausts system storage [1][2][3]. - Impact: This vulnerability affects any application or service that uses node-tar to extract archives provided by untrusted sources, such as CI/CD pipelines, file-sharing platforms, or package registries [1][5]. - Affected Versions: All versions <= 7.5.18 [1][2]. - Patched Version: 7.5.19 [1][4]. - GitHub Advisory ID: GHSA-23hp-3jrh-7fpw [1][3]. - Severity: Critical (CVSS 4.0 base score 9.2) [1][6]. Users are advised to upgrade to version 7.5.19 or later to mitigate this risk [4][6].
Citations:
🌐 Web query:
OSV GHSA-r277-6w6q-xmqw packages grafana kin-openapi💡 Result:
GHSA-r277-6w6q-xmqw is a critical severity (CVSS 9.1) authentication bypass vulnerability in the Go package getkin/kin-openapi [1][2]. The vulnerability occurs in the ValidationHandler.Load method, which incorrectly defaults to a NoopAuthenticationFunc when a nil AuthenticationFunc is provided [1][2]. Because the no-op function always returns nil (indicating success), any OpenAPI security requirements (such as API keys or OAuth tokens) in the specification are silently ignored [1][2]. This creates a fail-open condition where unauthenticated requests are permitted to access protected handlers [1][3][2]. This vulnerability impacts any application using kin-openapi's ValidationHandler as enforcement middleware if they rely on the default (nil) authentication configuration [1][2]. Because of the popularity and widespread use of the library, many projects, including various components within the Grafana ecosystem (such as grafana-plugin-sdk-go and others), have been identified as potentially affected or requiring dependency updates [4]. Users should update to a non-vulnerable version of getkin/kin-openapi where the issue is remediated. For instance, specific security advisories have tracked remediation across affected packages, including updates within Grafana-related distributions [5]. [1][2]
Citations:
🌐 Web query:
OSV CVE-2026-59873 packages node-tar💡 Result:
CVE-2026-59873 is a critical Denial of Service (DoS) vulnerability in the node-tar library for Node.js [1][2][3]. The vulnerability arises because the library fails to enforce hard upper bounds on total decompressed data, entry counts, or decompression ratios during archive extraction and parsing [2][4][3]. An attacker can exploit this flaw by providing a maliciously crafted archive—specifically a "Gzip Bomb"—that causes the system to exhaust disk space and CPU resources [1][3]. This can lead to system-wide failures and service outages for any application using node-tar to extract archives from untrusted sources [1][3]. Key details regarding the vulnerability include: - Affected Versions: All versions of node-tar <= 7.5.18 [1][3]. - Patched Version: The vulnerability is fixed in version 7.5.19 [1][2][4]. - Severity: Rated as Critical with a CVSS 4.0 base score of 9.2 [2][3][5]. - Weakness: Classified as CWE-770 (Allocation of Resources Without Limits or Throttling) [3]. Users are strongly advised to update to node-tar version 7.5.19 or later to mitigate this risk [1][2][3].
Citations:
🌐 Web query:
GitHub CVE-2026-59873 OpenSearch Dashboards node-tar💡 Result:
CVE-2026-59873 is a critical Denial of Service (DoS) vulnerability in the node-tar library (npm package 'tar') [1][2]. It is not a vulnerability specific to OpenSearch Dashboards, though OpenSearch Dashboards may be affected if it uses a vulnerable version of node-tar [1][3]. Vulnerability Details: The vulnerability arises because node-tar (versions 7.5.18 and below) fails to enforce hard upper bounds on total decompressed data, entry counts, or decompression ratios during extraction [1][2]. An attacker can provide a maliciously crafted "Gzip Bomb"—a small, compressed archive that expands into a massive amount of data—to cause resource exhaustion (disk space and CPU) on the server [1][2]. This can lead to system-wide failure or service outages [1][2]. Resolution: The issue was addressed and fixed in node-tar version 7.5.19 [1][4]. Users should upgrade to this version or higher to mitigate the risk [1][2]. Context regarding OpenSearch Dashboards: While OpenSearch Dashboards has experienced past security advisories related to its dependencies—including other issues in the node-tar library (e.g., CVE-2026-31802 and CVE-2026-26960)—CVE-2026-59873 is a separate, more recent issue affecting the upstream node-tar library itself [1][3][5]. Users of OpenSearch Dashboards should audit their environment for the vulnerable node-tar dependency and apply the necessary updates provided by the project maintainers if and when they issue a patch for the affected component [1][2].
Citations:
Confirm the dependency mapping before suppressing these critical advisories.
GHSA-r277-6w6q-xmqwaffectsgetkin/kin-openapibefore 0.144.0, andCVE-2026-59873affectsnode-tar<= 7.5.18. Add evidence that the deployed Grafana and OpenSearch Dashboards images include the vulnerable dependency versions, and add an owner plus an expiry or removal condition tied to the fixed package release or RPM build.Source: MCP tools