Skip to content

Conversation

@upodroid
Copy link
Member

@k8s-ci-robot k8s-ci-robot added the cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. label Oct 29, 2025
@k8s-ci-robot k8s-ci-robot added size/L Denotes a PR that changes 100-499 lines, ignoring generated files. area/images sig/testing Categorizes an issue or PR as relevant to SIG Testing. labels Oct 29, 2025
@k8s-ci-robot
Copy link
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: upodroid

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@k8s-ci-robot k8s-ci-robot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Oct 29, 2025
@BenTheElder
Copy link
Member

key CI images are out of date, and I'm seeing a lot of CVEs reported by Datadog in our CI clusters.

Exploiting these isn't very interesting though, we provide RCE by design ... often as root on a disposable CI environment.

However, we do need to be careful about being able to patch other issues while not being blocked on breaking CI.

E.G. in the past bumping gcloud has broken the rather fragile kube-up.sh, we used to ask test-infra folks to keep an eye out when running upgrades and handle rollbacks.

This tower of tech debt stinks, but we all only have so much time to chip away at it.

I'm a little hesitant, generally I'm in favor of staying up to date, fully patched, etc, but these are primarily out of date not because sending a PR to bump them is hard, but because nobody wants to expend energy on dealing with failures at the moment and we have some fragile bits (e.g. also the dind in this repo is ... something we should improve and sensitive to docker updates) ...

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. area/images cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. sig/testing Categorizes an issue or PR as relevant to SIG Testing. size/L Denotes a PR that changes 100-499 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants