-
Notifications
You must be signed in to change notification settings - Fork 563
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Upgrade mysql to 8.0.40 #10774
Upgrade mysql to 8.0.40 #10774
Conversation
f0c3026
to
7af1c25
Compare
Retargeted to fasttrack/2.0 |
SPECS/mysql/mysql.spec
Outdated
@@ -98,6 +97,10 @@ fi | |||
%{_libdir}/pkgconfig/mysqlclient.pc | |||
|
|||
%changelog | |||
* Fri Oct 18 2024 Sudipta Pandit <[email protected]> - 8.0.37-1 |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This should be version 8.0.40-1
SPECS/mysql/mysql.spec
Outdated
@@ -98,6 +97,10 @@ fi | |||
%{_libdir}/pkgconfig/mysqlclient.pc | |||
|
|||
%changelog | |||
* Fri Oct 18 2024 Sudipta Pandit <[email protected]> - 8.0.37-1 | |||
- Upgrade to 8.0.40 to fix CVE-2024-21096 |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Can you list the other CVEs fixed by this upgrade? Or mention that it fixes 19 CVES
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I have changed the word to multiple, as now I am seeing more CVEs will be fixed by this. Should I list all of them in changelog? or adding them to this GitHub PR description will work as well?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
It would be best to list all of the CVEs that we know are fixed
SPECS/mysql/mysql.spec
Outdated
@@ -98,6 +97,10 @@ fi | |||
%{_libdir}/pkgconfig/mysqlclient.pc | |||
|
|||
%changelog | |||
* Fri Oct 18 2024 Sudipta Pandit <[email protected]> - 8.0.37-1 |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
version number is wrong in changelog
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Fixed
(cherry picked from commit 91f8315)
Auto cherry-pick results: Auto cherry-pick pipeline run -> https://dev.azure.com/mariner-org/mariner/_build/results?buildId=661630&view=results |
Merge Checklist
All boxes should be checked before merging the PR (just tick any boxes which don't apply to this PR)
*-static
subpackages, etc.) have had theirRelease
tag incremented../cgmanifest.json
,./toolkit/scripts/toolchain/cgmanifest.json
,.github/workflows/cgmanifest.json
)./LICENSES-AND-NOTICES/SPECS/data/licenses.json
,./LICENSES-AND-NOTICES/SPECS/LICENSES-MAP.md
,./LICENSES-AND-NOTICES/SPECS/LICENSE-EXCEPTIONS.PHOTON
)*.signatures.json
filessudo make go-tidy-all
andsudo make go-test-coverage
passSummary
Fixes 40 CVEs --
CVE-2024-21193
CVE-2024-21194
CVE-2024-21162
CVE-2024-21157
CVE-2024-21130
CVE-2024-20996
CVE-2024-21129
CVE-2024-21159
CVE-2024-21135
CVE-2024-21173
CVE-2024-21160
CVE-2024-21125
CVE-2024-21134
CVE-2024-21127
CVE-2024-21142
CVE-2024-21166
CVE-2024-21163
CVE-2024-21203
CVE-2024-21219
CVE-2024-21247
CVE-2024-21237
CVE-2024-21231
CVE-2024-21213
CVE-2024-21218
CVE-2024-21197
CVE-2024-21230
CVE-2024-21207
CVE-2024-21201
CVE-2024-21198
CVE-2024-21238
CVE-2024-21196
CVE-2024-21239
CVE-2024-21199
CVE-2024-21241
CVE-2024-21236
CVE-2024-21212
CVE-2024-21096
CVE-2024-21171
CVE-2024-21165
CVE-2023-46219
Change Log
Does this affect the toolchain?
NO
Links to CVEs
Test Methodology