From 9c72ab5823fc28f96c5194406acce546e304f180 Mon Sep 17 00:00:00 2001 From: Matheus Macabu Date: Tue, 18 Feb 2025 10:10:45 +0100 Subject: [PATCH] [release-10.4.16] Chore: Update alpine docker image (minor) - 3.20.5 to 3.20.6 [security] (#100833) Chore: Update alpine docker image (minor) - 3.20.5 to 3.20.6 [security] (#100791) * Chore: Update alpine docker image (minor) - 3.20.5 to 3.20.6 [sec-fixes] * Chore: Regenerate .drone.yml --------- Co-authored-by: Matheus Macabu (cherry picked from commit 27837ee937217a74ac1d1cc547516fafd344fa5d) Co-authored-by: Robert Goltz --- .drone.yml | 68 ++++++++++++++++----------------- scripts/drone/utils/images.star | 2 +- 2 files changed, 35 insertions(+), 35 deletions(-) diff --git a/.drone.yml b/.drone.yml index 6aa98c75f5e..d9b309e6f29 100644 --- a/.drone.yml +++ b/.drone.yml @@ -18,7 +18,7 @@ services: [] steps: - commands: - echo $DRONE_RUNNER_NAME - image: alpine:3.20.5 + image: alpine:3.20.6 name: identify-runner - commands: - go build -o ./bin/build -ldflags '-extldflags -static' ./pkg/build/cmd @@ -69,7 +69,7 @@ services: [] steps: - commands: - echo $DRONE_RUNNER_NAME - image: alpine:3.20.5 + image: alpine:3.20.6 name: identify-runner - commands: - go install github.com/bazelbuild/buildtools/buildifier@latest @@ -112,7 +112,7 @@ services: [] steps: - commands: - echo $DRONE_RUNNER_NAME - image: alpine:3.20.5 + image: alpine:3.20.6 name: identify-runner - commands: - apk add --update g++ make python3 && ln -sf /usr/bin/python3 /usr/bin/python @@ -250,7 +250,7 @@ steps: path: /github-app - commands: - echo $DRONE_RUNNER_NAME - image: alpine:3.20.5 + image: alpine:3.20.6 name: identify-runner - commands: - apk add --update g++ make python3 && ln -sf /usr/bin/python3 /usr/bin/python @@ -360,7 +360,7 @@ steps: path: /github-app - commands: - echo $DRONE_RUNNER_NAME - image: alpine:3.20.5 + image: alpine:3.20.6 name: identify-runner - commands: - '# It is required that code generated from Thema/CUE be committed and in sync @@ -449,7 +449,7 @@ services: [] steps: - commands: - echo $DRONE_RUNNER_NAME - image: alpine:3.20.5 + image: alpine:3.20.6 name: identify-runner - commands: - go build -o ./bin/build -ldflags '-extldflags -static' ./pkg/build/cmd @@ -578,7 +578,7 @@ steps: path: /github-app - commands: - echo $DRONE_RUNNER_NAME - image: alpine:3.20.5 + image: alpine:3.20.6 name: identify-runner - commands: - mkdir -p bin @@ -679,7 +679,7 @@ steps: GF_APP_MODE: development GF_SERVER_HTTP_PORT: "3001" GF_SERVER_ROUTER_LOGGING: "1" - image: alpine:3.20.5 + image: alpine:3.20.6 name: grafana-server - commands: - ./bin/build e2e-tests --port 3001 --suite dashboards-suite @@ -812,7 +812,7 @@ steps: - /src/grafana-build artifacts -a docker:grafana:linux/amd64 -a docker:grafana:linux/amd64:ubuntu -a docker:grafana:linux/arm64 -a docker:grafana:linux/arm64:ubuntu -a docker:grafana:linux/arm/v7 -a docker:grafana:linux/arm/v7:ubuntu --yarn-cache=$$YARN_CACHE_FOLDER --build-id=$$DRONE_BUILD_NUMBER - --go-version=1.22.11 --ubuntu-base=ubuntu:22.04 --alpine-base=alpine:3.20.5 --tag-format='{{ + --go-version=1.22.11 --ubuntu-base=ubuntu:22.04 --alpine-base=alpine:3.20.6 --tag-format='{{ .version_base }}-{{ .buildID }}-{{ .arch }}' --grafana-dir=$$PWD --ubuntu-tag-format='{{ .version_base }}-{{ .buildID }}-ubuntu-{{ .arch }}' > docker.txt - find ./dist -name '*docker*.tar.gz' -type f | xargs -n1 docker load -i @@ -979,7 +979,7 @@ steps: name: compile-build-cmd - commands: - echo $DRONE_RUNNER_NAME - image: alpine:3.20.5 + image: alpine:3.20.6 name: identify-runner - commands: - '# It is required that code generated from Thema/CUE be committed and in sync @@ -1169,7 +1169,7 @@ services: [] steps: - commands: - echo $DRONE_RUNNER_NAME - image: alpine:3.20.5 + image: alpine:3.20.6 name: identify-runner - commands: - apk add --update g++ make python3 && ln -sf /usr/bin/python3 /usr/bin/python @@ -1556,7 +1556,7 @@ services: [] steps: - commands: - echo $DRONE_RUNNER_NAME - image: alpine:3.20.5 + image: alpine:3.20.6 name: identify-runner - commands: - apk add --update g++ make python3 && ln -sf /usr/bin/python3 /usr/bin/python @@ -1628,7 +1628,7 @@ services: [] steps: - commands: - echo $DRONE_RUNNER_NAME - image: alpine:3.20.5 + image: alpine:3.20.6 name: identify-runner - commands: - apk add --update g++ make python3 && ln -sf /usr/bin/python3 /usr/bin/python @@ -1687,7 +1687,7 @@ services: [] steps: - commands: - echo $DRONE_RUNNER_NAME - image: alpine:3.20.5 + image: alpine:3.20.6 name: identify-runner - commands: - apk add --update g++ make python3 && ln -sf /usr/bin/python3 /usr/bin/python @@ -1756,7 +1756,7 @@ services: [] steps: - commands: - echo $DRONE_RUNNER_NAME - image: alpine:3.20.5 + image: alpine:3.20.6 name: identify-runner - commands: - '# It is required that code generated from Thema/CUE be committed and in sync @@ -1837,7 +1837,7 @@ services: [] steps: - commands: - echo $DRONE_RUNNER_NAME - image: alpine:3.20.5 + image: alpine:3.20.6 name: identify-runner - commands: - go build -o ./bin/build -ldflags '-extldflags -static' ./pkg/build/cmd @@ -1926,7 +1926,7 @@ steps: path: /github-app - commands: - echo $DRONE_RUNNER_NAME - image: alpine:3.20.5 + image: alpine:3.20.6 name: identify-runner - commands: - mkdir -p bin @@ -2026,7 +2026,7 @@ steps: GF_APP_MODE: development GF_SERVER_HTTP_PORT: "3001" GF_SERVER_ROUTER_LOGGING: "1" - image: alpine:3.20.5 + image: alpine:3.20.6 name: grafana-server - commands: - ./bin/build e2e-tests --port 3001 --suite dashboards-suite @@ -2195,7 +2195,7 @@ steps: - /src/grafana-build artifacts -a docker:grafana:linux/amd64 -a docker:grafana:linux/amd64:ubuntu -a docker:grafana:linux/arm64 -a docker:grafana:linux/arm64:ubuntu -a docker:grafana:linux/arm/v7 -a docker:grafana:linux/arm/v7:ubuntu --yarn-cache=$$YARN_CACHE_FOLDER --build-id=$$DRONE_BUILD_NUMBER - --go-version=1.22.11 --ubuntu-base=ubuntu:22.04 --alpine-base=alpine:3.20.5 --tag-format='{{ + --go-version=1.22.11 --ubuntu-base=ubuntu:22.04 --alpine-base=alpine:3.20.6 --tag-format='{{ .version_base }}-{{ .buildID }}-{{ .arch }}' --grafana-dir=$$PWD --ubuntu-tag-format='{{ .version_base }}-{{ .buildID }}-ubuntu-{{ .arch }}' > docker.txt - find ./dist -name '*docker*.tar.gz' -type f | xargs -n1 docker load -i @@ -2407,7 +2407,7 @@ steps: name: compile-build-cmd - commands: - echo $DRONE_RUNNER_NAME - image: alpine:3.20.5 + image: alpine:3.20.6 name: identify-runner - commands: - '# It is required that code generated from Thema/CUE be committed and in sync @@ -2676,7 +2676,7 @@ services: [] steps: - commands: - echo $DRONE_RUNNER_NAME - image: alpine:3.20.5 + image: alpine:3.20.6 name: identify-runner - commands: - mkdir -p bin @@ -2808,7 +2808,7 @@ services: [] steps: - commands: - echo $DRONE_RUNNER_NAME - image: alpine:3.20.5 + image: alpine:3.20.6 name: identify-runner - commands: - mkdir -p bin @@ -3255,7 +3255,7 @@ steps: environment: _EXPERIMENTAL_DAGGER_CLOUD_TOKEN: from_secret: dagger_token - ALPINE_BASE: alpine:3.20.5 + ALPINE_BASE: alpine:3.20.6 CDN_DESTINATION: from_secret: rgm_cdn_destination DESTINATION: @@ -3330,7 +3330,7 @@ steps: environment: _EXPERIMENTAL_DAGGER_CLOUD_TOKEN: from_secret: dagger_token - ALPINE_BASE: alpine:3.20.5 + ALPINE_BASE: alpine:3.20.6 CDN_DESTINATION: from_secret: rgm_cdn_destination DESTINATION: @@ -3492,7 +3492,7 @@ steps: environment: _EXPERIMENTAL_DAGGER_CLOUD_TOKEN: from_secret: dagger_token - ALPINE_BASE: alpine:3.20.5 + ALPINE_BASE: alpine:3.20.6 CDN_DESTINATION: from_secret: rgm_cdn_destination DESTINATION: @@ -3594,7 +3594,7 @@ services: [] steps: - commands: - echo $DRONE_RUNNER_NAME - image: alpine:3.20.5 + image: alpine:3.20.6 name: identify-runner - commands: - apk add --update g++ make python3 && ln -sf /usr/bin/python3 /usr/bin/python @@ -3649,7 +3649,7 @@ services: [] steps: - commands: - echo $DRONE_RUNNER_NAME - image: alpine:3.20.5 + image: alpine:3.20.6 name: identify-runner - commands: - '# It is required that code generated from Thema/CUE be committed and in sync @@ -3731,7 +3731,7 @@ steps: environment: _EXPERIMENTAL_DAGGER_CLOUD_TOKEN: from_secret: dagger_token - ALPINE_BASE: alpine:3.20.5 + ALPINE_BASE: alpine:3.20.6 CDN_DESTINATION: from_secret: rgm_cdn_destination DESTINATION: @@ -3875,7 +3875,7 @@ steps: environment: _EXPERIMENTAL_DAGGER_CLOUD_TOKEN: from_secret: dagger_token - ALPINE_BASE: alpine:3.20.5 + ALPINE_BASE: alpine:3.20.6 CDN_DESTINATION: from_secret: rgm_cdn_destination DESTINATION: @@ -4001,7 +4001,7 @@ steps: environment: _EXPERIMENTAL_DAGGER_CLOUD_TOKEN: from_secret: dagger_token - ALPINE_BASE: alpine:3.20.5 + ALPINE_BASE: alpine:3.20.6 CDN_DESTINATION: from_secret: rgm_cdn_destination DESTINATION: @@ -4151,7 +4151,7 @@ steps: name: grabpl - commands: - echo $DRONE_RUNNER_NAME - image: alpine:3.20.5 + image: alpine:3.20.6 name: identify-runner - commands: - '# It is required that code generated from Thema/CUE be committed and in sync @@ -4598,7 +4598,7 @@ steps: - trivy --exit-code 0 --severity UNKNOWN,LOW,MEDIUM node:20.9.0-alpine - trivy --exit-code 0 --severity UNKNOWN,LOW,MEDIUM google/cloud-sdk:431.0.0 - trivy --exit-code 0 --severity UNKNOWN,LOW,MEDIUM grafana/grafana-ci-deploy:1.3.3 - - trivy --exit-code 0 --severity UNKNOWN,LOW,MEDIUM alpine:3.20.5 + - trivy --exit-code 0 --severity UNKNOWN,LOW,MEDIUM alpine:3.20.6 - trivy --exit-code 0 --severity UNKNOWN,LOW,MEDIUM ubuntu:22.04 - trivy --exit-code 0 --severity UNKNOWN,LOW,MEDIUM byrnedo/alpine-curl:0.1.8 - trivy --exit-code 0 --severity UNKNOWN,LOW,MEDIUM plugins/slack @@ -4636,7 +4636,7 @@ steps: - trivy --exit-code 1 --severity HIGH,CRITICAL node:20.9.0-alpine - trivy --exit-code 1 --severity HIGH,CRITICAL google/cloud-sdk:431.0.0 - trivy --exit-code 1 --severity HIGH,CRITICAL grafana/grafana-ci-deploy:1.3.3 - - trivy --exit-code 1 --severity HIGH,CRITICAL alpine:3.20.5 + - trivy --exit-code 1 --severity HIGH,CRITICAL alpine:3.20.6 - trivy --exit-code 1 --severity HIGH,CRITICAL ubuntu:22.04 - trivy --exit-code 1 --severity HIGH,CRITICAL byrnedo/alpine-curl:0.1.8 - trivy --exit-code 1 --severity HIGH,CRITICAL plugins/slack @@ -4901,6 +4901,6 @@ kind: secret name: gcr_credentials --- kind: signature -hmac: f187922c027237a33c123475dd49a7ecc8db73d49eae4340a74e1031586da8e8 +hmac: 2e0c337ada57bdaebd90d0c42a3b53ada3d2f7a242b975741d2af4ce647da5cb ... diff --git a/scripts/drone/utils/images.star b/scripts/drone/utils/images.star index 67e80a23a3a..05566f49a7d 100644 --- a/scripts/drone/utils/images.star +++ b/scripts/drone/utils/images.star @@ -15,7 +15,7 @@ images = { "node": "node:{}-alpine".format(nodejs_version), "cloudsdk": "google/cloud-sdk:431.0.0", "publish": "grafana/grafana-ci-deploy:1.3.3", - "alpine": "alpine:3.20.5", + "alpine": "alpine:3.20.6", "ubuntu": "ubuntu:22.04", "curl": "byrnedo/alpine-curl:0.1.8", "plugins_slack": "plugins/slack",