Skip to content

fix(kratos): migrate to image.yaml v2 and update ignored vulnerabilities - #1183

Merged
zhijie-yang merged 1 commit into
canonical:mainfrom
shipperizer:iam/kratos
Aug 24, 2026
Merged

fix(kratos): migrate to image.yaml v2 and update ignored vulnerabilities#1183
zhijie-yang merged 1 commit into
canonical:mainfrom
shipperizer:iam/kratos

Conversation

@shipperizer

Copy link
Copy Markdown
Contributor

This PR migrates the Kratos image trigger to schema version 2:

  • Update oci/kratos/image.yaml to version: 2
  • Update kratos rock commit to 054491506cf40c662c8b9f87b7e0bfac37c4a3fc
  • Add unresolvable active vulnerabilities to ignored-vulnerabilities with comments and links
  • Remove deprecated oci/kratos/.trivyignore

Comment thread oci/kratos/image.yaml
Comment thread oci/kratos/image.yaml

@alesancor1 alesancor1 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@zhijie-yang zhijie-yang left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Happy to approve this. Please pay attention to the comment here: #1182 (comment). Thanks.

@zhijie-yang
zhijie-yang merged commit e5e6118 into canonical:main Aug 24, 2026
16 checks passed
shipperizer added a commit to canonical/kratos-rock that referenced this pull request Aug 24, 2026
Bump canonical/identity-team reusable workflows to v1.16.0 (e017941885bd1d17774bf7be2cbbb1d1abe80d9e) and pass ignored vulnerabilities to the oci-publish job matching canonical/oci-factory#1183.
shipperizer added a commit to canonical/kratos-rock that referenced this pull request Aug 24, 2026
…ies (#311)

## Description

This PR updates the reusable GitHub Actions workflows from
`canonical/identity-team` to `v1.16.0`
(`e017941885bd1d17774bf7be2cbbb1d1abe80d9e`) and configures the
`ignore-vulnerabilities` input for OCI publishing.

### Details
- **identity-team workflows bump**: Updated all
`canonical/identity-team` workflow references to `v1.16.0`
(`e017941885bd1d17774bf7be2cbbb1d1abe80d9e`) in
`.github/workflows/ci.yaml`, `.github/workflows/cves.yaml`, and
`.github/workflows/auto-approver.yaml`.
- **Ignore vulnerabilities**: Exploits the new `ignore-vulnerabilities`
input added to `_rock-oci-publish.yaml` in
[canonical/identity-team#142](canonical/identity-team#142)
(released in `v1.16.0`).
- **Vulnerabilities list**: Passes the list of ignored vulnerabilities
from
[canonical/oci-factory#1183](canonical/oci-factory#1183)
(`oci/kratos/image.yaml`):
  - `CVE-2026-32286`
  - `CVE-2026-33818`
  - `CVE-2026-33997`
  - `CVE-2026-34040`
  - `CVE-2026-39821`
  - `CVE-2026-46600`
  - `CVE-2026-56853`
  - `CVE-2026-56858`
  - `CVE-2026-56859`
  - `CVE-2026-56860`
  - `CVE-2026-56862`
  - `GO-2026-5932`
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants