Go to file
Tara Subedi b45f7c1bb1 Update notificationservice-base-v2 for CVE fixes
There are extra CVEs found on notificationservice-base-v2 image
compared to other ptp images. Recently [1], image building
framework for notificationservice-base-v2 has been switched
from Docker to Loci, which inherited CVEs coming from fixed
Python and OS versions from loci script/stable-wheels.cfg [2]/
upper-constraints.txt [3].

This commit fixes CVEs by overriding affected Python and OS
packages locally in the image.

[1] https://review.opendev.org/c/starlingx/ptp-notification-armada-app/+/940259
[2] https://opendev.org/starlingx/root/src/branch/master/build-tools/build-wheels/debian/stable-wheels.cfg
[3] https://opendev.org/starlingx/root/src/branch/master/build-tools/build-wheels/debian/openstack-requirements/caracal/upper-constraints.txt

TEST PLAN:
PASS: successful build and deployment
PASS: No high severity vulnerabilities found
PASS: Sync status verified

Story: 2011332
Task: 52773

Change-Id: I89f09bb994cf6e55eaa1e5fc9926689dd41a20f5
Signed-off-by: Tara Nath Subedi <tara.subedi@windriver.com>
Signed-off-by: Eduardo Alberti <eduardo.alberti@windriver.com>
2025-09-04 10:31:36 -04:00
2022-05-31 14:33:17 +00:00
2021-01-19 18:53:24 +00:00
2023-12-20 06:36:14 -06:00
Description
StarlingX PTP Notification App
4.7 MiB
Languages
Python 97.3%
Makefile 1.2%
Shell 0.4%
Dockerfile 0.4%
Smarty 0.3%
Other 0.4%