-
Notifications
You must be signed in to change notification settings - Fork 133
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Bump version to 2.21.3 #275
Conversation
f33689c
to
bef12b9
Compare
CHANGELOG.md
Outdated
* Bug - Resolve IMDSv1 fallback error introduced in 2.21.0 [aws-for-fluent-bit:259](https://github.com/aws/aws-for-fluent-bit/issues/259) | ||
|
||
Important Note: | ||
* A security vulnerability was found in [amazonlinux](https://access.redhat.com/security/cve/CVE-2021-43527) which we use as base image to our `aws-for-fluent-bit` image. This new image will be based on an updated version of amazonlinux that resolves this CVE. It is highly recommended to upgrade your existing workload or run new workload with this latest version (2.21.3) of `aws-for-fluent-bit` image. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I thought we agreed we wouldn't put the "highly recommended" warning? And let customers decide how scared to be.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The forced push looks like it didn't make it through.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I edited this locally but the forced push looks like it didn't make it through.
AWS_FOR_FLUENT_BIT_STABLE_VERSION
Outdated
2.21.3 |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
sorry I missed this
we can;t bump stalbe until the new release is out
this will cause the automation to fial
Pulls latest amazonlinux as base image that includes a patch for HIGH CVE-2021-43527. Signed-off-by: Matthew Fala <[email protected]>
bef12b9
to
627f1ae
Compare
Same as `2.21.2`, this release includes the following fixes for AWS customers that we are working on getting accepted upstream: | ||
* Bug - Fix return value from `tls_net_read` [fluentbit:4098](https://github.com/fluent/fluent-bit/issues/4098) | ||
* Bug - Downgrade `mbedtls` to 2.24.0 to fix the performance regression issue in `mbedtls` 2.26.0 [fluentbit:4110](https://github.com/fluent/fluent-bit/issues/4110) | ||
* Bug - Resolve IMDSv1 fallback error introduced in 2.21.0 [aws-for-fluent-bit:259](https://github.com/aws/aws-for-fluent-bit/issues/259) |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I have a question, was your fix for this one merged into Fluent Bit?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
No, the PRs are all still open.
fluent/fluent-bit#4100
fluent/fluent-bit#4110
fluent/fluent-bit#4184
Pulls latest amazonlinux as base image that includes a patch for
HIGH CVE-2021-43527.
Signed-off-by: Matthew Fala [email protected]
Issue #, if available:
Description of changes:
By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the terms of your choice.