Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[security] Update redmine #9851

Merged
merged 1 commit into from Mar 24, 2021
Merged

Conversation

tianon
Copy link
Member

@tianon tianon commented Mar 24, 2021

Changes:

Changes:

- docker-library/redmine@3fdebe9: Merge pull request docker-library/redmine#230 from J0WI/fix-glibc-dep
- docker-library/redmine@d93440f: Update Dockerfile-alpine.template
@github-actions
Copy link

Diff for 9c87367:
diff --git a/_bashbrew-cat b/_bashbrew-cat
index 7cbfb2c..54df12c 100644
--- a/_bashbrew-cat
+++ b/_bashbrew-cat
@@ -1,28 +1,28 @@
 Maintainers: Tianon Gravi <admwiggin@gmail.com> (@tianon), Joseph Ferguson <yosifkit@gmail.com> (@yosifkit)
 GitRepo: https://github.com/docker-library/redmine.git
 
-Tags: 4.0.7, 4.0
+Tags: 4.0.8, 4.0
 Architectures: amd64, arm32v5, arm32v7, arm64v8, i386, mips64le, ppc64le, s390x
-GitCommit: f5895d1d4bff53a590b6048e294dc96b26206883
+GitCommit: ae11c0c35e0920781464c4afdac9096eec355c8b
 Directory: 4.0
 
-Tags: 4.0.7-alpine, 4.0-alpine
-GitCommit: e224c25360a7a576ec53fd105b403d2ce4b92d5b
+Tags: 4.0.8-alpine, 4.0-alpine
+GitCommit: d93440fe33185a141fc6fbee809cd7cd886acf84
 Directory: 4.0/alpine
 
-Tags: 4.0.7-passenger, 4.0-passenger
+Tags: 4.0.8-passenger, 4.0-passenger
 GitCommit: 7fdd6777cc21b0d1974884e6e54208d16a991b19
 Directory: 4.0/passenger
 
-Tags: 4.1.1, 4.1, 4, latest
+Tags: 4.1.2, 4.1, 4, latest
 Architectures: amd64, arm32v5, arm32v7, arm64v8, i386, mips64le, ppc64le, s390x
-GitCommit: f5895d1d4bff53a590b6048e294dc96b26206883
+GitCommit: ea093b382fbdb883daf868c5ea4a9c1fd27f3aca
 Directory: 4.1
 
-Tags: 4.1.1-alpine, 4.1-alpine, 4-alpine, alpine
-GitCommit: e224c25360a7a576ec53fd105b403d2ce4b92d5b
+Tags: 4.1.2-alpine, 4.1-alpine, 4-alpine, alpine
+GitCommit: d93440fe33185a141fc6fbee809cd7cd886acf84
 Directory: 4.1/alpine
 
-Tags: 4.1.1-passenger, 4.1-passenger, 4-passenger, passenger
+Tags: 4.1.2-passenger, 4.1-passenger, 4-passenger, passenger
 GitCommit: 7fdd6777cc21b0d1974884e6e54208d16a991b19
 Directory: 4.1/passenger
diff --git a/_bashbrew-list b/_bashbrew-list
index e051978..1a019b6 100644
--- a/_bashbrew-list
+++ b/_bashbrew-list
@@ -4,15 +4,15 @@ redmine:4-passenger
 redmine:4.0
 redmine:4.0-alpine
 redmine:4.0-passenger
-redmine:4.0.7
-redmine:4.0.7-alpine
-redmine:4.0.7-passenger
+redmine:4.0.8
+redmine:4.0.8-alpine
+redmine:4.0.8-passenger
 redmine:4.1
 redmine:4.1-alpine
 redmine:4.1-passenger
-redmine:4.1.1
-redmine:4.1.1-alpine
-redmine:4.1.1-passenger
+redmine:4.1.2
+redmine:4.1.2-alpine
+redmine:4.1.2-passenger
 redmine:alpine
 redmine:latest
 redmine:passenger
diff --git a/redmine_4.0-alpine/Dockerfile b/redmine_4.0-alpine/Dockerfile
index 0512d4b..6a727cd 100644
--- a/redmine_4.0-alpine/Dockerfile
+++ b/redmine_4.0-alpine/Dockerfile
@@ -37,12 +37,12 @@ RUN set -eux; \
 	chown redmine:redmine "$HOME"; \
 	chmod 1777 "$HOME"
 
-ENV REDMINE_VERSION 4.0.7
-ENV REDMINE_DOWNLOAD_MD5 baad690fdccd7f0282d53beb0ee2c47b
+ENV REDMINE_VERSION 4.0.8
+ENV REDMINE_DOWNLOAD_SHA256 c06ebd75ab87b23d766b37a9e49c9e456756ed91f85b33a584a66f47f888038a
 
 RUN set -eux; \
 	wget -O redmine.tar.gz "https://www.redmine.org/releases/redmine-${REDMINE_VERSION}.tar.gz"; \
-	echo "$REDMINE_DOWNLOAD_MD5 *redmine.tar.gz" | md5sum -c -; \
+	echo "$REDMINE_DOWNLOAD_SHA256 *redmine.tar.gz" | sha256sum -c -; \
 	tar -xf redmine.tar.gz --strip-components=1; \
 	rm redmine.tar.gz files/delete.me log/delete.me; \
 	mkdir -p log public/plugin_assets sqlite tmp/pdf tmp/pids; \
@@ -53,6 +53,8 @@ RUN set -eux; \
 	chmod -R ugo=rwX config db sqlite; \
 	find log tmp -type d -exec chmod 1777 '{}' +
 
+# build for musl-libc, not glibc (see https://github.com/sparklemotion/nokogiri/issues/2075, https://github.com/rubygems/rubygems/issues/3174)
+ENV BUNDLE_FORCE_RUBY_PLATFORM 1
 RUN set -eux; \
 	\
 	apk add --no-cache --virtual .build-deps \
diff --git a/redmine_4.0/Dockerfile b/redmine_4.0/Dockerfile
index 7199493..61abc32 100644
--- a/redmine_4.0/Dockerfile
+++ b/redmine_4.0/Dockerfile
@@ -77,12 +77,12 @@ RUN set -eux; \
 	chown redmine:redmine "$HOME"; \
 	chmod 1777 "$HOME"
 
-ENV REDMINE_VERSION 4.0.7
-ENV REDMINE_DOWNLOAD_MD5 baad690fdccd7f0282d53beb0ee2c47b
+ENV REDMINE_VERSION 4.0.8
+ENV REDMINE_DOWNLOAD_SHA256 c06ebd75ab87b23d766b37a9e49c9e456756ed91f85b33a584a66f47f888038a
 
 RUN set -eux; \
 	wget -O redmine.tar.gz "https://www.redmine.org/releases/redmine-${REDMINE_VERSION}.tar.gz"; \
-	echo "$REDMINE_DOWNLOAD_MD5 *redmine.tar.gz" | md5sum -c -; \
+	echo "$REDMINE_DOWNLOAD_SHA256 *redmine.tar.gz" | sha256sum -c -; \
 	tar -xf redmine.tar.gz --strip-components=1; \
 	rm redmine.tar.gz files/delete.me log/delete.me; \
 	mkdir -p log public/plugin_assets sqlite tmp/pdf tmp/pids; \
diff --git a/redmine_alpine/Dockerfile b/redmine_alpine/Dockerfile
index 18ea43d..95693bc 100644
--- a/redmine_alpine/Dockerfile
+++ b/redmine_alpine/Dockerfile
@@ -38,12 +38,12 @@ RUN set -eux; \
 	chown redmine:redmine "$HOME"; \
 	chmod 1777 "$HOME"
 
-ENV REDMINE_VERSION 4.1.1
-ENV REDMINE_DOWNLOAD_MD5 a15a25dec7b866e213bbd4b041f05f17
+ENV REDMINE_VERSION 4.1.2
+ENV REDMINE_DOWNLOAD_SHA256 7e22397351c53fe8fe4444c01c4e0640d9cefb17b9ac765b846df27627cd228e
 
 RUN set -eux; \
 	wget -O redmine.tar.gz "https://www.redmine.org/releases/redmine-${REDMINE_VERSION}.tar.gz"; \
-	echo "$REDMINE_DOWNLOAD_MD5 *redmine.tar.gz" | md5sum -c -; \
+	echo "$REDMINE_DOWNLOAD_SHA256 *redmine.tar.gz" | sha256sum -c -; \
 	tar -xf redmine.tar.gz --strip-components=1; \
 	rm redmine.tar.gz files/delete.me log/delete.me; \
 	mkdir -p log public/plugin_assets sqlite tmp/pdf tmp/pids; \
@@ -54,6 +54,8 @@ RUN set -eux; \
 	chmod -R ugo=rwX config db sqlite; \
 	find log tmp -type d -exec chmod 1777 '{}' +
 
+# build for musl-libc, not glibc (see https://github.com/sparklemotion/nokogiri/issues/2075, https://github.com/rubygems/rubygems/issues/3174)
+ENV BUNDLE_FORCE_RUBY_PLATFORM 1
 RUN set -eux; \
 	\
 	apk add --no-cache --virtual .build-deps \
diff --git a/redmine_latest/Dockerfile b/redmine_latest/Dockerfile
index 9cbd5da..bd25ff5 100644
--- a/redmine_latest/Dockerfile
+++ b/redmine_latest/Dockerfile
@@ -78,12 +78,12 @@ RUN set -eux; \
 	chown redmine:redmine "$HOME"; \
 	chmod 1777 "$HOME"
 
-ENV REDMINE_VERSION 4.1.1
-ENV REDMINE_DOWNLOAD_MD5 a15a25dec7b866e213bbd4b041f05f17
+ENV REDMINE_VERSION 4.1.2
+ENV REDMINE_DOWNLOAD_SHA256 7e22397351c53fe8fe4444c01c4e0640d9cefb17b9ac765b846df27627cd228e
 
 RUN set -eux; \
 	wget -O redmine.tar.gz "https://www.redmine.org/releases/redmine-${REDMINE_VERSION}.tar.gz"; \
-	echo "$REDMINE_DOWNLOAD_MD5 *redmine.tar.gz" | md5sum -c -; \
+	echo "$REDMINE_DOWNLOAD_SHA256 *redmine.tar.gz" | sha256sum -c -; \
 	tar -xf redmine.tar.gz --strip-components=1; \
 	rm redmine.tar.gz files/delete.me log/delete.me; \
 	mkdir -p log public/plugin_assets sqlite tmp/pdf tmp/pids; \

@yosifkit yosifkit merged commit df4bd97 into docker-library:master Mar 24, 2021
@yosifkit yosifkit deleted the redmine branch March 24, 2021 18:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

3 participants