Merge "Update base image with latest security fixes"

This commit is contained in:
Zuul 2018-04-18 07:15:12 +00:00 committed by Gerrit Code Review
commit dba0aee4d9
2 changed files with 10 additions and 3 deletions

View File

@ -145,7 +145,8 @@ RUN rpm --import /etc/pki/rpm-gpg/RPM-GPG-KEY-CentOS-7
rpm --import {{ key }} \ rpm --import {{ key }} \
{% endfor -%} {% endfor -%}
{%- if base_centos_yum_repo_keys|customizable('centos_yum_repo_keys')|length == 0 %}RUN {% else %} && {% endif -%} {%- if base_centos_yum_repo_keys|customizable('centos_yum_repo_keys')|length == 0 %}RUN {% else %} && {% endif -%}
yum clean all yum -y update --security --sec-severity=Important --sec-severity=Critical \
&& yum clean all
{% endif %} {% endif %}
{# Endif for base_distro centos #} {# Endif for base_distro centos #}
@ -161,11 +162,12 @@ RUN yum -y install \
&& yum-config-manager --enable rhel-7-server-optional-rpms \ && yum-config-manager --enable rhel-7-server-optional-rpms \
&& yum -y install \ && yum -y install \
yum-plugin-priorities \ yum-plugin-priorities \
&& yum clean all \
&& yum-config-manager --enable rhel-7-server-extras-rpms \ && yum-config-manager --enable rhel-7-server-extras-rpms \
&& yum-config-manager --enable rhel-7-server-rhceph-2-osd-rpms \ && yum-config-manager --enable rhel-7-server-rhceph-2-osd-rpms \
&& yum-config-manager --enable rhel-7-server-rhceph-2-mon-rpms \ && yum-config-manager --enable rhel-7-server-rhceph-2-mon-rpms \
&& yum-config-manager --enable rhel-7-server-rhceph-2-tools-rpms && yum-config-manager --enable rhel-7-server-rhceph-2-tools-rpms \
&& yum -y update --security --sec-severity=Important --sec-severity=Critical \
&& yum clean all
{% endblock %} {% endblock %}
{% endif %} {% endif %}
@ -193,6 +195,7 @@ RUN yum -y install \
&& yum-config-manager --enable ol7_optional_latest ol7_addons \ && yum-config-manager --enable ol7_optional_latest ol7_addons \
&& yum -y install \ && yum -y install \
yum-plugin-priorities \ yum-plugin-priorities \
&& yum -y update --security --sec-severity=Important --sec-severity=Critical \
&& yum clean all && yum clean all
{% endblock %} {% endblock %}

View File

@ -0,0 +1,4 @@
---
features:
- RPM based container images now include the latest security fixes available
at the time of build.