Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[SECURITY] Redis Release 6.2.17, 7.2.7, 7.4.2 #18190

Merged

Conversation

@adamiBs adamiBs requested review from LaurentGoderre and a team as code owners January 6, 2025 15:37

This comment was marked as outdated.

LaurentGoderre
LaurentGoderre previously approved these changes Jan 6, 2025

This comment was marked as outdated.

@LaurentGoderre
Copy link
Member

LaurentGoderre commented Jan 6, 2025

@adamiBs can we merge this one before this gets in? redis/docker-library-redis#428

@adamiBs
Copy link
Contributor Author

adamiBs commented Jan 6, 2025

@LaurentGoderre

@adamiBs can we merge this one before this gets in? redis/docker-library-redis#428

Thanks for the contribution! 🙂
I've bumped the commit SHA now - in order to include the updated version of Alpine.

This comment was marked as outdated.

Copy link

github-actions bot commented Jan 6, 2025

Diff for a4dc2d9:
diff --git a/_bashbrew-cat b/_bashbrew-cat
index e9e3db6..47b0244 100644
--- a/_bashbrew-cat
+++ b/_bashbrew-cat
@@ -1,34 +1,34 @@
 Maintainers: Adam Ben Shmuel <adam.ben-shmuel@redis.com> (@adamiBs), Yossi Gottlieb <yossi@redis.com> (@yossigo)
 GitRepo: https://github.com/redis/docker-library-redis.git
 
-Tags: 6.2.16, 6.2, 6, 6.2.16-bookworm, 6.2-bookworm, 6-bookworm
+Tags: 6.2.17, 6.2, 6, 6.2.17-bookworm, 6.2-bookworm, 6-bookworm
 Architectures: amd64, arm32v5, arm32v7, arm64v8, i386, mips64le, ppc64le, s390x
-GitCommit: e5650da99bb377b2ed4f9f1ef993ff24729b1c16
+GitCommit: 8338d86bc3f7b195046138f8c31bf9a839cdedd3
 Directory: 6.2/debian
 
-Tags: 6.2.16-alpine, 6.2-alpine, 6-alpine, 6.2.16-alpine3.20, 6.2-alpine3.20, 6-alpine3.20
+Tags: 6.2.17-alpine, 6.2-alpine, 6-alpine, 6.2.17-alpine3.21, 6.2-alpine3.21, 6-alpine3.21
 Architectures: amd64, arm32v6, arm32v7, arm64v8, i386, ppc64le, riscv64, s390x
-GitCommit: e5650da99bb377b2ed4f9f1ef993ff24729b1c16
+GitCommit: 8338d86bc3f7b195046138f8c31bf9a839cdedd3
 Directory: 6.2/alpine
 
-Tags: 7.2.6, 7.2, 7.2.6-bookworm, 7.2-bookworm
+Tags: 7.2.7, 7.2, 7.2.7-bookworm, 7.2-bookworm
 Architectures: amd64, arm32v5, arm32v7, arm64v8, i386, mips64le, ppc64le, s390x
-GitCommit: e5650da99bb377b2ed4f9f1ef993ff24729b1c16
+GitCommit: 8338d86bc3f7b195046138f8c31bf9a839cdedd3
 Directory: 7.2/debian
 
-Tags: 7.2.6-alpine, 7.2-alpine, 7.2.6-alpine3.20, 7.2-alpine3.20
+Tags: 7.2.7-alpine, 7.2-alpine, 7.2.7-alpine3.21, 7.2-alpine3.21
 Architectures: amd64, arm32v6, arm32v7, arm64v8, i386, ppc64le, riscv64, s390x
-GitCommit: e5650da99bb377b2ed4f9f1ef993ff24729b1c16
+GitCommit: 8338d86bc3f7b195046138f8c31bf9a839cdedd3
 Directory: 7.2/alpine
 
-Tags: 7.4.1, 7.4, 7, latest, 7.4.1-bookworm, 7.4-bookworm, 7-bookworm, bookworm
+Tags: 7.4.2, 7.4, 7, latest, 7.4.2-bookworm, 7.4-bookworm, 7-bookworm, bookworm
 Architectures: amd64, arm32v5, arm32v7, arm64v8, i386, mips64le, ppc64le, s390x
-GitCommit: e5650da99bb377b2ed4f9f1ef993ff24729b1c16
+GitCommit: 8338d86bc3f7b195046138f8c31bf9a839cdedd3
 Directory: 7.4/debian
 
-Tags: 7.4.1-alpine, 7.4-alpine, 7-alpine, alpine, 7.4.1-alpine3.20, 7.4-alpine3.20, 7-alpine3.20, alpine3.20
+Tags: 7.4.2-alpine, 7.4-alpine, 7-alpine, alpine, 7.4.2-alpine3.21, 7.4-alpine3.21, 7-alpine3.21, alpine3.21
 Architectures: amd64, arm32v6, arm32v7, arm64v8, i386, ppc64le, riscv64, s390x
-GitCommit: e5650da99bb377b2ed4f9f1ef993ff24729b1c16
+GitCommit: 8338d86bc3f7b195046138f8c31bf9a839cdedd3
 Directory: 7.4/alpine
 
 Tags: 8.0-M02, 8.0-M02-bookworm
@@ -37,7 +37,7 @@ GitFetch: refs/heads/release/8.0
 GitCommit: f1e991818a8124502b5a4e8e6c7f4ae23d0c7bb4
 Directory: debian
 
-Tags: 8.0-M02-alpine, 8.0-M02-alpine3.20
+Tags: 8.0-M02-alpine, 8.0-M02-alpine3.21
 Architectures: amd64, arm32v6, arm32v7, arm64v8, i386, ppc64le, riscv64, s390x
 GitFetch: refs/heads/release/8.0
 GitCommit: f1e991818a8124502b5a4e8e6c7f4ae23d0c7bb4
diff --git a/_bashbrew-list b/_bashbrew-list
index 11fca67..0378889 100644
--- a/_bashbrew-list
+++ b/_bashbrew-list
@@ -1,40 +1,40 @@
 redis:6
 redis:6-alpine
-redis:6-alpine3.20
+redis:6-alpine3.21
 redis:6-bookworm
 redis:6.2
 redis:6.2-alpine
-redis:6.2-alpine3.20
+redis:6.2-alpine3.21
 redis:6.2-bookworm
-redis:6.2.16
-redis:6.2.16-alpine
-redis:6.2.16-alpine3.20
-redis:6.2.16-bookworm
+redis:6.2.17
+redis:6.2.17-alpine
+redis:6.2.17-alpine3.21
+redis:6.2.17-bookworm
 redis:7
 redis:7-alpine
-redis:7-alpine3.20
+redis:7-alpine3.21
 redis:7-bookworm
 redis:7.2
 redis:7.2-alpine
-redis:7.2-alpine3.20
+redis:7.2-alpine3.21
 redis:7.2-bookworm
-redis:7.2.6
-redis:7.2.6-alpine
-redis:7.2.6-alpine3.20
-redis:7.2.6-bookworm
+redis:7.2.7
+redis:7.2.7-alpine
+redis:7.2.7-alpine3.21
+redis:7.2.7-bookworm
 redis:7.4
 redis:7.4-alpine
-redis:7.4-alpine3.20
+redis:7.4-alpine3.21
 redis:7.4-bookworm
-redis:7.4.1
-redis:7.4.1-alpine
-redis:7.4.1-alpine3.20
-redis:7.4.1-bookworm
+redis:7.4.2
+redis:7.4.2-alpine
+redis:7.4.2-alpine3.21
+redis:7.4.2-bookworm
 redis:8.0-M02
 redis:8.0-M02-alpine
-redis:8.0-M02-alpine3.20
+redis:8.0-M02-alpine3.21
 redis:8.0-M02-bookworm
 redis:alpine
-redis:alpine3.20
+redis:alpine3.21
 redis:bookworm
 redis:latest
diff --git a/_bashbrew-list-build-order b/_bashbrew-list-build-order
index 2bbd7e5..67dab71 100644
--- a/_bashbrew-list-build-order
+++ b/_bashbrew-list-build-order
@@ -1,8 +1,8 @@
-redis:6-alpine3.20
+redis:6-alpine3.21
 redis:6-bookworm
-redis:7.2-alpine3.20
+redis:7.2-alpine3.21
 redis:7.2-bookworm
-redis:8.0-M02-alpine3.20
+redis:8.0-M02-alpine3.21
 redis:8.0-M02-bookworm
-redis:alpine3.20
+redis:alpine3.21
 redis:bookworm
diff --git a/redis_6-alpine3.20/Dockerfile b/redis_6-alpine3.21/Dockerfile
similarity index 97%
rename from redis_6-alpine3.20/Dockerfile
rename to redis_6-alpine3.21/Dockerfile
index b7c7ba8..65ad72e 100644
--- a/redis_6-alpine3.20/Dockerfile
+++ b/redis_6-alpine3.21/Dockerfile
@@ -4,7 +4,7 @@
 # PLEASE DO NOT EDIT IT DIRECTLY.
 #
 
-FROM alpine:3.20
+FROM alpine:3.21
 
 # add our user and group first to make sure their IDs get assigned consistently, regardless of whatever dependencies get added
 RUN set -eux; \
@@ -49,9 +49,9 @@ RUN set -eux; \
 	gosu --version; \
 	gosu nobody true
 
-ENV REDIS_VERSION 6.2.16
-ENV REDIS_DOWNLOAD_URL http://download.redis.io/releases/redis-6.2.16.tar.gz
-ENV REDIS_DOWNLOAD_SHA 846bff83c26d827d49f8cc8114ea9d1e72eea1169f7de36b8135ea2cec104e7d
+ENV REDIS_VERSION 6.2.17
+ENV REDIS_DOWNLOAD_URL http://download.redis.io/releases/redis-6.2.17.tar.gz
+ENV REDIS_DOWNLOAD_SHA f7aab300407aaa005bc1a688e61287111f4ae13ed657ec50ef4ab529893ddc30
 
 RUN set -eux; \
 	\
diff --git a/redis_6-alpine3.20/docker-entrypoint.sh b/redis_6-alpine3.21/docker-entrypoint.sh
similarity index 100%
rename from redis_6-alpine3.20/docker-entrypoint.sh
rename to redis_6-alpine3.21/docker-entrypoint.sh
diff --git a/redis_6-bookworm/Dockerfile b/redis_6-bookworm/Dockerfile
index 3a64589..f58171f 100644
--- a/redis_6-bookworm/Dockerfile
+++ b/redis_6-bookworm/Dockerfile
@@ -56,9 +56,9 @@ RUN set -eux; \
 	gosu --version; \
 	gosu nobody true
 
-ENV REDIS_VERSION 6.2.16
-ENV REDIS_DOWNLOAD_URL http://download.redis.io/releases/redis-6.2.16.tar.gz
-ENV REDIS_DOWNLOAD_SHA 846bff83c26d827d49f8cc8114ea9d1e72eea1169f7de36b8135ea2cec104e7d
+ENV REDIS_VERSION 6.2.17
+ENV REDIS_DOWNLOAD_URL http://download.redis.io/releases/redis-6.2.17.tar.gz
+ENV REDIS_DOWNLOAD_SHA f7aab300407aaa005bc1a688e61287111f4ae13ed657ec50ef4ab529893ddc30
 
 RUN set -eux; \
 	\
diff --git a/redis_alpine3.20/Dockerfile b/redis_7.2-alpine3.21/Dockerfile
similarity index 97%
rename from redis_alpine3.20/Dockerfile
rename to redis_7.2-alpine3.21/Dockerfile
index d02dce6..ce72457 100644
--- a/redis_alpine3.20/Dockerfile
+++ b/redis_7.2-alpine3.21/Dockerfile
@@ -4,7 +4,7 @@
 # PLEASE DO NOT EDIT IT DIRECTLY.
 #
 
-FROM alpine:3.20
+FROM alpine:3.21
 
 # add our user and group first to make sure their IDs get assigned consistently, regardless of whatever dependencies get added
 RUN set -eux; \
@@ -49,9 +49,9 @@ RUN set -eux; \
 	gosu --version; \
 	gosu nobody true
 
-ENV REDIS_VERSION 7.4.1
-ENV REDIS_DOWNLOAD_URL http://download.redis.io/releases/redis-7.4.1.tar.gz
-ENV REDIS_DOWNLOAD_SHA bc34b878eb89421bbfca6fa78752343bf37af312a09eb0fae47c9575977dfaa2
+ENV REDIS_VERSION 7.2.7
+ENV REDIS_DOWNLOAD_URL http://download.redis.io/releases/redis-7.2.7.tar.gz
+ENV REDIS_DOWNLOAD_SHA 72c081e3b8cfae7144273d26d76736f08319000af46c01515cad5d29765cead5
 
 RUN set -eux; \
 	\
diff --git a/redis_7.2-alpine3.20/docker-entrypoint.sh b/redis_7.2-alpine3.21/docker-entrypoint.sh
similarity index 100%
rename from redis_7.2-alpine3.20/docker-entrypoint.sh
rename to redis_7.2-alpine3.21/docker-entrypoint.sh
diff --git a/redis_7.2-bookworm/Dockerfile b/redis_7.2-bookworm/Dockerfile
index 388f52d..bc175b3 100644
--- a/redis_7.2-bookworm/Dockerfile
+++ b/redis_7.2-bookworm/Dockerfile
@@ -56,9 +56,9 @@ RUN set -eux; \
 	gosu --version; \
 	gosu nobody true
 
-ENV REDIS_VERSION 7.2.6
-ENV REDIS_DOWNLOAD_URL http://download.redis.io/releases/redis-7.2.6.tar.gz
-ENV REDIS_DOWNLOAD_SHA fb10d67a2fe2b4556f6cb840064dd6e6e3175ce8ca035f0726990ec2da9f3d0e
+ENV REDIS_VERSION 7.2.7
+ENV REDIS_DOWNLOAD_URL http://download.redis.io/releases/redis-7.2.7.tar.gz
+ENV REDIS_DOWNLOAD_SHA 72c081e3b8cfae7144273d26d76736f08319000af46c01515cad5d29765cead5
 
 RUN set -eux; \
 	\
diff --git a/redis_8.0-M02-alpine3.20/Dockerfile b/redis_8.0-M02-alpine3.21/Dockerfile
similarity index 100%
rename from redis_8.0-M02-alpine3.20/Dockerfile
rename to redis_8.0-M02-alpine3.21/Dockerfile
diff --git a/redis_8.0-M02-alpine3.20/docker-entrypoint.sh b/redis_8.0-M02-alpine3.21/docker-entrypoint.sh
similarity index 100%
rename from redis_8.0-M02-alpine3.20/docker-entrypoint.sh
rename to redis_8.0-M02-alpine3.21/docker-entrypoint.sh
diff --git a/redis_7.2-alpine3.20/Dockerfile b/redis_alpine3.21/Dockerfile
similarity index 97%
rename from redis_7.2-alpine3.20/Dockerfile
rename to redis_alpine3.21/Dockerfile
index 5aa0b42..179e998 100644
--- a/redis_7.2-alpine3.20/Dockerfile
+++ b/redis_alpine3.21/Dockerfile
@@ -4,7 +4,7 @@
 # PLEASE DO NOT EDIT IT DIRECTLY.
 #
 
-FROM alpine:3.20
+FROM alpine:3.21
 
 # add our user and group first to make sure their IDs get assigned consistently, regardless of whatever dependencies get added
 RUN set -eux; \
@@ -49,9 +49,9 @@ RUN set -eux; \
 	gosu --version; \
 	gosu nobody true
 
-ENV REDIS_VERSION 7.2.6
-ENV REDIS_DOWNLOAD_URL http://download.redis.io/releases/redis-7.2.6.tar.gz
-ENV REDIS_DOWNLOAD_SHA fb10d67a2fe2b4556f6cb840064dd6e6e3175ce8ca035f0726990ec2da9f3d0e
+ENV REDIS_VERSION 7.4.2
+ENV REDIS_DOWNLOAD_URL http://download.redis.io/releases/redis-7.4.2.tar.gz
+ENV REDIS_DOWNLOAD_SHA 4ddebbf09061cbb589011786febdb34f29767dd7f89dbe712d2b68e808af6a1f
 
 RUN set -eux; \
 	\
diff --git a/redis_alpine3.20/docker-entrypoint.sh b/redis_alpine3.21/docker-entrypoint.sh
similarity index 100%
rename from redis_alpine3.20/docker-entrypoint.sh
rename to redis_alpine3.21/docker-entrypoint.sh
diff --git a/redis_bookworm/Dockerfile b/redis_bookworm/Dockerfile
index 9d7fff1..79c7002 100644
--- a/redis_bookworm/Dockerfile
+++ b/redis_bookworm/Dockerfile
@@ -56,9 +56,9 @@ RUN set -eux; \
 	gosu --version; \
 	gosu nobody true
 
-ENV REDIS_VERSION 7.4.1
-ENV REDIS_DOWNLOAD_URL http://download.redis.io/releases/redis-7.4.1.tar.gz
-ENV REDIS_DOWNLOAD_SHA bc34b878eb89421bbfca6fa78752343bf37af312a09eb0fae47c9575977dfaa2
+ENV REDIS_VERSION 7.4.2
+ENV REDIS_DOWNLOAD_URL http://download.redis.io/releases/redis-7.4.2.tar.gz
+ENV REDIS_DOWNLOAD_SHA 4ddebbf09061cbb589011786febdb34f29767dd7f89dbe712d2b68e808af6a1f
 
 RUN set -eux; \
 	\

Relevant Maintainers:

@LaurentGoderre
Copy link
Member

@adamiBs it seems the tags were not updated though and are still saying alpine 3.20

@LaurentGoderre
Copy link
Member

@adamiBs it seems the tags were not updated though and are still saying alpine 3.20

Beat me to it!

@adamiBs
Copy link
Contributor Author

adamiBs commented Jan 6, 2025

My bad, forgot to update the tags twice 🤦🏼
Was a bit hasty since this relates to a security fix I guess 🙃

@LaurentGoderre
Copy link
Member

@adamiBs no worries! All hands on deck!

@LaurentGoderre
Copy link
Member

@adamiBs do you mind if I squash this to one commit when merging?

@adamiBs
Copy link
Contributor Author

adamiBs commented Jan 6, 2025

Sure

@LaurentGoderre LaurentGoderre merged commit 171c466 into docker-library:master Jan 6, 2025
13 checks passed
@adamiBs
Copy link
Contributor Author

adamiBs commented Jan 6, 2025

Thanks for the fast response! @LaurentGoderre

@yosifkit
Copy link
Member

yosifkit commented Jan 6, 2025

It looks like the tag for 8.0-M02-alpine got updated to say it is alpine 3.21, but there isn't a corresponding Dockerfile change. Can the Dockerfile be updated and a PR submitted to update the library/redis file?

-Tags: 8.0-M02-alpine, 8.0-M02-alpine3.20
+Tags: 8.0-M02-alpine, 8.0-M02-alpine3.21

diff --git a/redis_8.0-M02-alpine3.20/Dockerfile b/redis_8.0-M02-alpine3.21/Dockerfile
similarity index 100%
rename from redis_8.0-M02-alpine3.20/Dockerfile
rename to redis_8.0-M02-alpine3.21/Dockerfile

@LaurentGoderre
Copy link
Member

redis/docker-library-redis#429

@LaurentGoderre
Copy link
Member

@adamiBs thanks for the heads up btw

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants