Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

2.31.8 CVE patch release #627

Merged
merged 2 commits into from
Apr 6, 2023
Merged

2.31.8 CVE patch release #627

merged 2 commits into from
Apr 6, 2023

Conversation

Claych
Copy link
Contributor

@Claych Claych commented Apr 5, 2023

Issue #, if available:

Description of changes:

By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the terms of your choice.

@Claych Claych requested a review from a team as a code owner April 5, 2023 21:34
CHANGELOG.md Outdated
* Amazon Kinesis Firehose for Fluent Bit 1.7.1

Compared to `2.31.7` this release adds:
* Feature - Added the process of building debug and init-debug images to the main pipeline, and sending them to [Amazon ECR Public Gallery](https://gallery.ecr.aws/aws-observability/aws-for-fluent-bit), [Docker Hub](https://hub.docker.com/r/amazon/aws-for-fluent-bit) and Amazon ECR. For debug images, we update the `debug-latest` tag and add a tag as `debug-<Version>`.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

customers don't care about our pipeline: and also I htink this isn't quite a feature:

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ack

windows.versions Outdated
Comment on lines 7 to 9
"kinesis-plugin": "v1.10.1",
"firehose-plugin": "v1.7.1",
"cloudwatch-plugin": "v1.9.2",
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The go plugins should be updated as well, remember I noted on Monday we need to create a new tag in reach repo for dependency upgrades.

"cloudwatch-plugin": "v1.9.2",
"openssl": "3.0.7",
"flexBison": "2.5.22",
"latest": true,
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

please ensure latest is set to false in 2.31.7.

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

!!!!!

* Amazon Kinesis Streams for Fluent Bit 1.10.1
* Amazon Kinesis Firehose for Fluent Bit 1.7.1

Compared to `2.31.7` this release adds:
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@Claych since I merged the init gov cloud fix it also is going out in this release too I think. Needs to be called out or reverted.

We're not supposed to add features in CVE releases, so technically we should revert it. Just in case my change introduced a bug which would block folks from consuming the CVE fixes.

https://github.com/aws/aws-for-fluent-bit/commits/mainline

Signed-off-by: Clay Cheng <[email protected]>
@Claych Claych merged commit 99cb89d into aws:mainline Apr 6, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants