b45f7c1bb1de6051979a23122e4720dad5e98ee4
There are extra CVEs found on notificationservice-base-v2 image compared to other ptp images. Recently [1], image building framework for notificationservice-base-v2 has been switched from Docker to Loci, which inherited CVEs coming from fixed Python and OS versions from loci script/stable-wheels.cfg [2]/ upper-constraints.txt [3]. This commit fixes CVEs by overriding affected Python and OS packages locally in the image. [1] https://review.opendev.org/c/starlingx/ptp-notification-armada-app/+/940259 [2] https://opendev.org/starlingx/root/src/branch/master/build-tools/build-wheels/debian/stable-wheels.cfg [3] https://opendev.org/starlingx/root/src/branch/master/build-tools/build-wheels/debian/openstack-requirements/caracal/upper-constraints.txt TEST PLAN: PASS: successful build and deployment PASS: No high severity vulnerabilities found PASS: Sync status verified Story: 2011332 Task: 52773 Change-Id: I89f09bb994cf6e55eaa1e5fc9926689dd41a20f5 Signed-off-by: Tara Nath Subedi <tara.subedi@windriver.com> Signed-off-by: Eduardo Alberti <eduardo.alberti@windriver.com>
Description
StarlingX PTP Notification App
Languages
Python
97.3%
Makefile
1.2%
Shell
0.4%
Dockerfile
0.4%
Smarty
0.3%
Other
0.4%