chore: update valkey source and version - #1179
Conversation
zhijie-yang
left a comment
There was a problem hiding this comment.
Please observe the CVE findings: https://github.com/canonical/oci-factory/actions/runs/32130713608/attempts/1#summary-95693045758
|
@zhijie-yang can you please re-trigger the build. The metrics exporter which had the CVEs has been rebuilt with a patched go version. |
|
the CI is triggered by your commit. let's see if this passes. |
|
@zhijie-yang green CI |
There was a problem hiding this comment.
Thanks for the changes! The following comment is generated using the AGENTS.md in the feature branch in OpenCode with the GPT-5.6 Sol (xhigh effort). I affirm all the comments are legit.
The source bump introduces release-policy and recipe blockers.
oci/valkey/documentation.yaml:8 — [blocker] The source migration leaves the published issues and source-code links pointing to canonical/charmed-valkey-rock; update them to the new canonical/valkey-artifacts repository. (§5)
The latest vulnerability scan is clean: https://github.com/canonical/oci-factory/actions/runs/32855920817/job/97846045027
| directory: ./valkey/rocks/standard | ||
| release: | ||
| 7.2.12-24.04: | ||
| 7.2.13-24.04: |
There was a problem hiding this comment.
[blocker] This modified SemVer track includes the patch component; use 7.2-24.04 rather than 7.2.13-24.04. (§3)
| 7.2.13-24.04: | |
| 7.2-24.04: |
| 7.2.13-24.04: | ||
| end-of-life: "2029-04-01T00:00:00Z" | ||
| risks: | ||
| - stable |
There was a problem hiding this comment.
[blocker] This is the first release of a new track, so it must start with edge only rather than stable. (§3)
| - stable | |
| - edge |
| - source: "canonical/valkey-artifacts" | ||
| commit: 252920e17d56e097efd0323e26a4ebdcb68312d7 | ||
| directory: ./valkey/rocks/standard | ||
| release: |
There was a problem hiding this comment.
[blocker] The pinned recipe stages .deb packages (lines 51-54), but its manifest part (lines 98-106) is hand-written. Please use https://github.com/canonical/rocks-security-manifest, wired exactly as its README specifies. (§4)
| directory: . | ||
| - source: "canonical/valkey-artifacts" | ||
| commit: 252920e17d56e097efd0323e26a4ebdcb68312d7 | ||
| directory: ./valkey/rocks/standard |
There was a problem hiding this comment.
[blocker] This source bump drops the previous recipe’s redis_exporter part (old lines 49-57) and replaces it with a staged package. Is this intentional? Please confirm it is not a regression, or restore the part. (§4)
Description
Update the valkey image source to the new valkey artifacts meta-repository and version to 7.2.13.