From e1ba8503ecbbeebce0e9acf327878328d8b98eb0 Mon Sep 17 00:00:00 2001 From: Alexander Vollschwitz Date: Thu, 3 Nov 2022 09:38:35 +0100 Subject: [PATCH] upgrades: Go 1.18.8, latest Ubuntu 22.04 (CVE remediation), Alpine 3.16, Skope 1.9.3 --- Makefile | 13 +++++++------ hack/dregsy.alpine.Dockerfile | 4 ++-- hack/dregsy.ubuntu.Dockerfile | 4 ++-- 3 files changed, 11 insertions(+), 10 deletions(-) diff --git a/Makefile b/Makefile index 8ce0734..04d1bbe 100644 --- a/Makefile +++ b/Makefile @@ -19,7 +19,7 @@ SHELL = /bin/bash REPO = dregsy DREGSY_VERSION = $$(git describe --always --tag --dirty) -SKOPEO_VERSION = v1.8.0 +SKOPEO_VERSION = v1.9.3 # https://github.com/containers/skopeo/releases ROOT = $(shell pwd) BUILD_OUTPUT =_build @@ -27,11 +27,12 @@ BINARIES = $(BUILD_OUTPUT)/bin ISOLATED_PKG = $(BUILD_OUTPUT)/pkg ISOLATED_CACHE = $(BUILD_OUTPUT)/cache -GO_IMAGE = golang:1.18.3 -GO_IMAGE_DIGEST_amd64 = 5417b4917fa7ed3ad2678a3ce6378a00c95bfd430c2ffa39936fce55130b5f2c -GO_IMAGE_DIGEST_arm64 = f9dd8baf438f408e37393c61dcd6daa467d87014c98def6469f369e825152aa1 -GO_IMAGE_DIGEST_arm = 730c46572958e35e8db6086f2763277b0b10dc215f58073568f1a803510fde30 -GO_IMAGE_DIGEST_386 = 41e9ae4681786bbacfe1645b0bbed650002bf347b5d360287b7522e823d64291 +GO_IMAGE = golang:1.18.8 +# use digests of plain golang:{x:y:z} image +GO_IMAGE_DIGEST_amd64 = 0fb1e79db0084e49cd4169612c6f7b7d414a1dba59072997cd3ac3ae1d725361 # linux/amd64 +GO_IMAGE_DIGEST_arm64 = 7abe674dc8d8708d3939c7cebfebe135ec9323a47f03dd80931320548c19bbcc # linux/arm64/v8 +GO_IMAGE_DIGEST_arm = f3ccf45fc02a293875f2b7634d632feed9ade9d4f34f2f1f76b38f3a2fcda596 # linux/arm/v7 +GO_IMAGE_DIGEST_386 = 17eaea98be41d69a7389fa8859e5da6b9bcc74ee99607b60dc941738d50edf6c # linux/386 GOOS = $(shell uname -s | tr A-Z a-z) GOARCH = $(shell ./hack/devenvutil get_architecture) diff --git a/hack/dregsy.alpine.Dockerfile b/hack/dregsy.alpine.Dockerfile index 703d21c..429f073 100644 --- a/hack/dregsy.alpine.Dockerfile +++ b/hack/dregsy.alpine.Dockerfile @@ -16,7 +16,7 @@ # Skopeo build, taken from https://github.com/bdwyertech/docker-skopeo # -FROM golang:1.18.3-alpine3.15@sha256:a1c4b28a06d5fce9b1e52b09930e240d24b00dfa85879df023f2ea7201bbe026 as skopeo +FROM golang:1.18.8-alpine3.16@sha256:6b494c932ee8c209631e27521ddbe364da56e7f1275998fbb182447d20103e46 as skopeo ARG SKOPEO_VERSION @@ -32,7 +32,7 @@ RUN apk add --no-cache --virtual .build-deps \ # dregsy image # -FROM alpine:3.15.4@sha256:a777c9c66ba177ccfea23f2a216ff6721e78a662cd17019488c417135299cd89 +FROM alpine:3.16.2@sha256:1304f174557314a7ed9eddb4eab12fed12cb0cd9809e4c28f29af86979a3c870 LABEL maintainer "vollschwitz@gmx.net" diff --git a/hack/dregsy.ubuntu.Dockerfile b/hack/dregsy.ubuntu.Dockerfile index 6cc9dc0..01f37a0 100644 --- a/hack/dregsy.ubuntu.Dockerfile +++ b/hack/dregsy.ubuntu.Dockerfile @@ -16,7 +16,7 @@ # Skopeo build # -FROM golang:1.18.3@sha256:5417b4917fa7ed3ad2678a3ce6378a00c95bfd430c2ffa39936fce55130b5f2c as skopeo +FROM golang:1.18.8@sha256:0fb1e79db0084e49cd4169612c6f7b7d414a1dba59072997cd3ac3ae1d725361 as skopeo ARG SKOPEO_VERSION @@ -32,7 +32,7 @@ RUN apt-get update \ # dregsy image # -FROM docker.io/ubuntu:22.04@sha256:aa6c2c047467afc828e77e306041b7fa4a65734fe3449a54aa9c280822b0d87d +FROM docker.io/ubuntu:22.04@sha256:817cfe4672284dcbfee885b1a66094fd907630d610cab329114d036716be49ba LABEL maintainer "vollschwitz@gmx.net"