UNCLASSIFIED
Skip to content
GitLab
Projects
Groups
Snippets
Help
Loading...
Help
Help
Support
Community forum
Keyboard shortcuts
?
Submit feedback
Sign in
Toggle navigation
Open sidebar
Ironbank Containers
Bitnami
airflow-worker
Commits
3e3636ef
Commit
3e3636ef
authored
May 04, 2021
by
Austin Denton
Browse files
Merge branch 'sato-66' into 'development'
Fix conditional approval issues See merge request
!18
parents
00014985
6631424d
Pipeline
#243981
failed with stages
in 3 minutes and 11 seconds
Changes
3
Pipelines
1
Hide whitespace changes
Inline
Side-by-side
Showing
3 changed files
with
10 additions
and
2 deletions
+10
-2
Dockerfile
Dockerfile
+2
-0
README.md
README.md
+2
-1
hardening_manifest.yaml
hardening_manifest.yaml
+6
-1
No files found.
Dockerfile
View file @
3e3636ef
...
@@ -39,6 +39,8 @@ RUN /opt/bitnami/scripts/airflow-worker/postunpack.sh && \
...
@@ -39,6 +39,8 @@ RUN /opt/bitnami/scripts/airflow-worker/postunpack.sh && \
tar xfz /local/wheels/thrift-0.14.1.tar.gz -C /local/wheels && \
tar xfz /local/wheels/thrift-0.14.1.tar.gz -C /local/wheels && \
pip install --no-index --no-deps /local/wheels/thrift-0.14.1/lib/py && \
pip install --no-index --no-deps /local/wheels/thrift-0.14.1/lib/py && \
rm -rf /local/wheels/thrift-0.14.1* && \
rm -rf /local/wheels/thrift-0.14.1* && \
# Remove Elasticsearch 7.5.1 due to high findings CVE-2020-7019 CVE-2020-7021 CVE-2020-7020 CVE-2020-7014 CVE-2020-7009
rm -rf /opt/bitnami/airflow/venv/lib/python3.8/site-packages/elasticsearch && rm -rf /opt/bitnami/airflow/venv/lib/python3.8/site-packages/elasticsearch-7.5* && \
for f in $(ls -l /local/wheels | awk '{print $9}' |sed '/^$/d'); do pip install --no-index --no-deps /local/wheels/$f; done && \
for f in $(ls -l /local/wheels | awk '{print $9}' |sed '/^$/d'); do pip install --no-index --no-deps /local/wheels/$f; done && \
find /opt/bitnami/airflow/venv/lib/python3.8/site-packages -name "*.pem" -o -name "*.key" | egrep ".*test.*/.*\.pem|.*test.*/.*\.key" | xargs rm -f && \
find /opt/bitnami/airflow/venv/lib/python3.8/site-packages -name "*.pem" -o -name "*.key" | egrep ".*test.*/.*\.pem|.*test.*/.*\.key" | xargs rm -f && \
chmod +x /opt/bitnami/scripts/* && \
chmod +x /opt/bitnami/scripts/* && \
...
...
README.md
View file @
3e3636ef
...
@@ -3,7 +3,8 @@
...
@@ -3,7 +3,8 @@
> Airflow is a platform to programmatically author, schedule and monitor workflows.
> Airflow is a platform to programmatically author, schedule and monitor workflows.
https://airflow.apache.org/
https://airflow.apache.org/
### Ironbank Hardened Image Notes:
apache-airflow-providers-elasticsearch will not work on this image due to vulnerabilities with Elasticsearch 7.5.1 (Removed)
# TL;DR
# TL;DR
## Docker Compose
## Docker Compose
...
...
hardening_manifest.yaml
View file @
3e3636ef
...
@@ -73,10 +73,15 @@ resources:
...
@@ -73,10 +73,15 @@ resources:
validation
:
validation
:
type
:
sha256
type
:
sha256
value
:
6ad9c7bdf517a808242b998ac20063c41532a570d088d77eec1ee12b0b5574bc
value
:
6ad9c7bdf517a808242b998ac20063c41532a570d088d77eec1ee12b0b5574bc
-
filename
:
astroid-2.5.1-py3-none-any.whl
url
:
https://files.pythonhosted.org/packages/f1/49/d51e5ce77ea234ee416966e489283512a9852f78d9ff125747eae29e7b69/astroid-2.5.1-py3-none-any.whl
validation
:
type
:
sha256
value
:
21d735aab248253531bb0f1e1e6d068f0ee23533e18ae8a6171ff892b98297cf
# List of project maintainers
# List of project maintainers
maintainers
:
maintainers
:
-
name
:
"
Austin
Denton"
-
name
:
"
Austin
Denton"
username
:
"
austindenton"
username
:
"
austindenton"
email
:
"
austindenton@seed-innovations.com"
email
:
"
austindenton@seed-innovations.com"
cht_member
:
false
cht_member
:
false
\ No newline at end of file
Write
Preview
Markdown
is supported
0%
Try again
or
attach a new file
.
Attach a file
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to comment