Last open CVE fixed as of 1.0.0~rc6+git20181203.96ec2177-0~ubuntu2 backports are in all releases. So past CVEs are no more part of the discussion.
Subscription already done for the server Team - thanks Josh. This is in the security Teams review queue (which is the proper next step). I wanted to summarize after the discussion about Go-vendoring at the recent sprint: - we expect (as in Docker) to handle runc/containerd special for SRUs providing an upstream experience which means regular MRE updates. - due to that over time we will have to move the GO dependencies forward which we can't for de-vendorized packages - Therefore it was agreed that we will do an initial check if a few could be used de-vendorized that are already done (e.g. due to former LXD activities) but not de-vendorize/MIR new packages. - We will provide a list of used vendorized code and tags/commits of it to security for their tracking for alerts - Going forward on updates we will check if some of them will then have to switch from de-vendorized to vendorized code. In that case we will keep security updated with the new list of vendored code for their tracking for alerts. -- TODOs (other than the ongoing security review) --- @Andreas will at some point do a check which (of the many) dependencies could (right now) be used from pre-de-vendorized packages - security had a particular interest in golang-golang-x-crypto-dev which was already in main for Juju (bug 1267393) but no more has a dep holding it in at the moment. A bunch more are in bug 1711317 bug 1520679 bug 1711265 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1817336 Title: [MIR] runc To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/runc/+bug/1817336/+subscriptions -- ubuntu-bugs mailing list [email protected] https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
