-
Notifications
You must be signed in to change notification settings - Fork 190
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Debian security vulnerabilities #303
Comments
Hi @Kala09 Thanks for creating the issue. I have some preliminary work done on updating the image here: https://github.com/jjethwa/icinga2/tree/bookworm There does seem to be a problem with Icinga Director on the latest PHP version though, it throws a few warnings upon starting and then will throw the similar warnings in the Icinga Web 2 UI upon loading one of the Director pages the first time. Functionality seems to be unaffected once the PHP resources are compiled though. It looks like the Director team already know this and are working up update the code so it's compatible. To prevent users from having issues, I won't update the image to Debian Bookworm until Director is fully compatible. If you don't need Director at this time, you can clone and build off the bookworm branch mentioned above. I'll keep this issue open until we can finally release it to the master branch. |
Hi @Kala09 Updated the Director references and it looks like we are good to go! I'll submit a PR and push a build to latest. Let me know if you have any issues. |
Hi @Kala09 Thanks for the added information. The build does an update to pull the latest package versions, so it looks like we need to wait for the upstream project updates to make it to the Debian repo. Let's leave this issue open for now and check back next week |
Sure @jjethwa , thank you |
Hi @jjethwa , can you please let me know if there is any possibility to cleared the above critical vulnerabilities? Looks like new debian bookworm version is released on jan11, 2025. Can you please have a look if this release could fix the vulnerability's? |
Hi @Kala09 I just kicked off a new build. It successfully ran and pushed to latest. Can you run your security tool against it? By the way, what tool is it? I might be able to automate it into the build process. |
Hi,
Is there any chance of upgrading the debian package from 11 to 12? Currently we noticed multiple security vulnerabilities in debian 11 package and the image is blocking within our organisation.
The text was updated successfully, but these errors were encountered: