From 7e6615585e4cdeb01ec4dd588615fa8db5ce2324 Mon Sep 17 00:00:00 2001 From: Michael Son <micson@deloitte.com> Date: Wed, 10 Apr 2024 09:40:53 -0400 Subject: [PATCH] cve updates --- Dockerfile | 4 ++-- hardening_manifest.yaml | 13 +++++-------- 2 files changed, 7 insertions(+), 10 deletions(-) diff --git a/Dockerfile b/Dockerfile index 63114c3..2cc04ba 100644 --- a/Dockerfile +++ b/Dockerfile @@ -7,10 +7,10 @@ USER 0 # Copy and extract ELRR Aggregator source cod WORKDIR / -COPY ./elrraggregator-2.1.tar.gz . +COPY ./elrraggregator-2.2.tar.gz . # ELRR Aggregator Dependencies -RUN tar -xvf ./elrraggregator-2.1.tar.gz --strip-components=1 && \ +RUN tar -xvf ./elrraggregator-2.2.tar.gz --strip-components=1 && \ mkdir -p target/dependency WORKDIR /elrraggregator-0.0.1-SNAPSHOT diff --git a/hardening_manifest.yaml b/hardening_manifest.yaml index 730c742..8a9a4e8 100644 --- a/hardening_manifest.yaml +++ b/hardening_manifest.yaml @@ -8,7 +8,7 @@ name: "opensource/adl-initiative/elrr/elrr-aggregator" # The most specific version should be the first tag and will be shown # on ironbank.dsop.io tags: -- "2.1.0" +- "2.2" - "latest" # Build args passed to Dockerfile-COPY ARGs @@ -24,18 +24,18 @@ labels: org.opencontainers.image.licenses: "Oracle Technology Network License" org.opencontainers.image.url: "https://github.com/US-ELRR/elrraggregator" org.opencontainers.image.vendor: "Enterprise Learner Record Repository (ELRR)" - org.opencontainers.image.version: "2.1.0" + org.opencontainers.image.version: "2.2" mil.dso.ironbank.image.keywords: "elrr, aggregator, elrraggregator, enterprise learner record repository" # Product the image belongs to for grouping multiple images mil.dso.ironbank.product.name: "Enterprise Learner Record Repository (ELRR)" # List of resources to make available to the offline build context resources: -- url: "https://github.com/US-ELRR/elrraggregator/archive/refs/tags/v2.1.tar.gz" - filename: "elrraggregator-2.1.tar.gz" +- url: "https://github.com/US-ELRR/elrraggregator/archive/refs/tags/v2.2.tar.gz" + filename: "elrraggregator-2.2.tar.gz" validation: type: "sha256" - value: "75e66d2fe63a8c3ec6fc6b3cad71cd1feab2db5d270486b19ffbcb597068c333" + value: "be91ff2e320af858f9af67cfef18265a7e274fe0806383f9c223d74f4fc57744" # List of project maintainers maintainers: @@ -45,8 +45,5 @@ maintainers: - email: "micson@deloitte.com" name: "Michael Son" username: "micson-us" -- email: "smednick@deloitte.com" - name: "Seth Mednick" - username: "smednick" -- GitLab