Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade from debian 11 (bullseye) to debian 12 (bookworm) #2517

Merged
merged 1 commit into from
Oct 8, 2023

Conversation

yob
Copy link
Contributor

@yob yob commented Oct 8, 2023

Debian 12 was released in June 2023 and has a range of package updates. The vast majority will not be significant in the context of the docs app and should have no impact on the app behaviour.

Updating is useful though, mainly just so we don't fall behind. It will also avoid some CVEs being detected by scanning software.

The critical CVE doesn't impact us, but here's the details: CVE-2023-38408.

2023-10-09_10-02

The CVE is also fixed in bullseye so this upgrade isn't technically required, we could also install security packages . I reckon the OS bump is worth or for other reasons though.

2023-10-09_10-06

/cc @buildkite/platform

Debian 12 was released in June 2023 and has a range of package updates.
The vast majority will not be significant in the context of the docs app
and should have no impact on the app behaviour.

Updating is useful though, mainly just so we don't fall behind. It will
also avoid some CVEs being detected by scanning software.

[1] https://wiki.debian.org/DebianBookworm
@yob yob requested review from clbarrell and dannymidnight October 8, 2023 23:08
@buildkite-docs-bot
Copy link
Contributor

Preview URL: https://2517--bk-docs-preview.netlify.app

@dannymidnight dannymidnight merged commit 7ceb193 into main Oct 8, 2023
1 check passed
@dannymidnight dannymidnight deleted the debian-bookworm branch October 8, 2023 23:38
@dannymidnight
Copy link
Contributor

Thanks @yob :)

yob added a commit that referenced this pull request Oct 9, 2023
In #2517 I upgrade docs frm debian 11 to 12, but I was surprised to see
that CVE-2023-38408 is sitll being detected post-upgrade.

I think it's because the patched openssh is available in the debian
security repositories. If so, adding this upgade should fetch them.
yob added a commit that referenced this pull request Oct 9, 2023
In #2517 I upgrade docs frm debian 11 to 12, but I was surprised to see
that CVE-2023-38408 is sitll being detected post-upgrade.

I think it's because the patched openssh is available in the debian
security repositories. If so, adding this upgade should fetch them.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants