Skip to content

chore(deps): bump d8 CLI to v0.33.22 in CVE scan template - #167

Closed
alexey-igrychev wants to merge 1 commit into
mainfrom
chore/deps/d8-0-33-22
Closed

alexey-igrychev wants to merge 1 commit into
mainfrom
chore/deps/d8-0-33-22

Conversation

@alexey-igrychev

Copy link
Copy Markdown

Summary

Update the CVE scan template's d8 pin from v0.29.24 to v0.33.22.

What

  • Download the v0.33.22 linux-amd64 release into the existing versioned binary cache path; keep extraction and secret-resolution logic unchanged.
  • VERIFIED: the old and new released binaries produce identical token, JSON-data and extracted-value output for the template's stronghold write and stronghold read commands against a local mock Vault API.
  • VERIFIED: the new release retains the expected tarball layout and runs on a musl-only Linux image.
  • UNVERIFIED: authentication with a real GitLab OIDC token and a complete CVE scan pipeline; the mock check does not establish server-side authorization.

Why

The previous pin predates the Go ELF signer in deckhouse/deckhouse-cli#493. Updating the explicit version delivers that implementation without changing how jobs locate the binary or resolve their secrets.

The CVE scan template pinned deckhouse-cli v0.29.24. Move the pin to
v0.33.22, which ships the SDK 1.4.2 update (deckhouse-cli#493).

Only the pinned version changes; the stronghold login and secret
resolution commands are untouched.

Signed-off-by: Aleksei Igrychev <aleksei.igrychev@palark.com>
@alexey-igrychev

Copy link
Copy Markdown
Author

Verification

  • Verified published checksums and linux-amd64/bin/d8 archive layout for both pins.
  • Replayed the template's two stronghold commands with the v0.29.24 and v0.33.22 linux-amd64 binaries inside an Alpine container against a local fake API. Token output, -field=data --format=json output and jq-extracted values matched; request method, login body and token header were checked.
  • Parsed the changed YAML and ran bash -n on both extracted script blocks. No production credentials or endpoints were used.

Follow-up

  • Run a CVE scan pipeline with its real GitLab identity on a test project before marking ready.

@alexey-igrychev

Copy link
Copy Markdown
Author

Closed without merging: the CVE scan template version bump is dropped from this SDK rollout at the requester’s direction. No CVE scan pipeline follow-up is required by this task.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant