-
Notifications
You must be signed in to change notification settings - Fork 104
Periodic sync of OKD samples #710
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Open
aroyoredhat
wants to merge
1
commit into
openshift:main
Choose a base branch
from
aroyoredhat:periodic-okd-sync
base: main
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
+34
−13
Open
Changes from all commits
Commits
File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🔒 Security & Privacy | 🟠 Major | ⚡ Quick win
🧩 Analysis chain
🏁 Script executed:
Repository: openshift/cluster-samples-operator
Length of output: 216
🏁 Script executed:
Repository: openshift/cluster-samples-operator
Length of output: 4994
🌐 Web query:
Open Liberty 26.0.0.7 26.0.0.8 release security vulnerabilities official💡 Result:
Open Liberty versions 26.0.0.7 and 26.0.0.8 address multiple security vulnerabilities. Official information for these releases is available through the Open Liberty documentation and security advisories [1][2][3]. Open Liberty 26.0.0.8 (released August 11, 2026) addressed the following CVEs: - CVE-2026-50645 (CVSS 7.5, Denial of Service) [1][2] - CVE-2026-9322 (CVSS 7.5, Denial of Service) [1][2] - CVE-2026-9171 (CVSS 7.5, Denial of Service) [1][2] - CVE-2026-9563 (CVSS 7.5, Denial of Service) [1][2] - CVE-2026-10842 (CVSS 7.5, Security Bypass) [1][2] - CVE-2026-11897 (CVSS 7.5, Denial of Service) [1][2] - CVE-2026-15057 (CVSS 7.5, Denial of Service) [1][2] Open Liberty 26.0.0.7 (released July 14, 2026) addressed the following CVEs: - CVE-2026-8646 (CVSS 8.1, HTTP Request Smuggling) [2][3] - CVE-2026-9320 (CVSS 5.9, Denial of Service) [3] - CVE-2026-9071 (CVSS 7.1, Denial of Service) [2][3] - CVE-2026-42402 (CVSS 7.5, Denial of Service) [3] - CVE-2026-42403 (CVSS 7.5, Denial of Service) [3] - CVE-2026-42404 (CVSS 7.2, Server-Side Request Forgery) [3] - CVE-2026-11806 (CVSS 7.2, HTTP Request Smuggling) [3] - CVE-2026-11541 (CVSS 7.4, HTTP Request Smuggling) [3] Users are encouraged to review the official Open Liberty security vulnerability documentation to determine if their specific server configurations and enabled features are affected [2][4]. Additionally, IBM provides supplemental security fix information for WebSphere Application Server Liberty, which may include interim fixes (iFixes) for specific vulnerabilities [5][6][7].
Citations:
🌐 Web query:
site:openliberty.io/docs/latest/security-vulnerabilities.html 26.0.0.7 26.0.0.8💡 Result:
The terms 26.0.0.7 and 26.0.0.8 refer to version releases of the Open Liberty application server [1]. Open Liberty security documentation indicates that 26.0.0.8 is a subsequent release following 26.0.0.7 [1]. The versions are frequently referenced in security advisory tables, where vulnerabilities affecting older versions (often cited as ranging from 17.0.0.3 up to 26.0.0.7) are resolved in 26.0.0.8 [1]. Similarly, vulnerabilities affecting versions up to 26.0.0.6 were resolved in 26.0.0.7 [1].
Citations:
🏁 Script executed:
Repository: openshift/cluster-samples-operator
Length of output: 1024
🌐 Web query:
site:github.com/OpenLiberty/open-liberty-s2i 26.0.0.8-java8💡 Result:
The term 26.0.0.8-java8 refers to a specific container image tag associated with the Open Liberty Source-to-Image (S2I) project [1]. This tag follows the naming convention used by the Open Liberty S2I project, where images are versioned according to the underlying Open Liberty release (e.g., 26.0.0.8) and the Java runtime environment (e.g., java8) [2][3]. The S2I project provides these images on the IBM Container Registry (icr.io) to facilitate building and running Open Liberty applications in OpenShift or other containerized environments [1][3]. While the Open Liberty S2I repository has documented releases up to version 26.0.0.6 and commit activity related to version 26.0.0.7 [3][4], tags following this pattern are generated consistently for each new version of Open Liberty [2][5]. The 26.0.0.8-java8 tag designates an image based on Open Liberty version 26.0.0.8 configured with Java 8 [1][3].
Citations:
🏁 Script executed:
Repository: openshift/cluster-samples-operator
Length of output: 942
🌐 Web query:
Open Liberty 26.0.0.7 security vulnerabilities fixed version official release July 2026💡 Result:
Open Liberty 26.0.0.7 was officially released on July 14, 2026 [1][2][3]. Regarding security, Open Liberty 26.0.0.7 introduced fixes for several vulnerabilities, including [4]: - CVE-2026-8646 (HTTP request smuggling) [4] - CVE-2026-9320 (Denial of service) [4] - CVE-2026-9071 (Denial of service) [4] - CVE-2026-42402 (Denial of service) [4] - CVE-2026-42403 (Denial of service) [4] - CVE-2026-42404 (Server-Side Request Forgery) [4] - CVE-2026-11806 (HTTP request smuggling) [4] It is important to note that subsequent security issues identified in versions 17.0.0.3 through 26.0.0.7—such as CVE-2026-11897 and CVE-2026-15057—were remediated in the subsequent release, Open Liberty 26.0.0.8, which was released on August 11, 2026 [5][6][7]. Users running version 26.0.0.7 are advised to upgrade to 26.0.0.8 or later to address these additional vulnerabilities [5][6][7].
Citations:
Do not reference unpublished Open Liberty S2I tags.
All four
26.0.0.7-*and26.0.0.8-*tags return HTTP 404 fromicr.io. Restore the ImageStream entries to the published26.0.0.6-*tags, or defer this change until the required security-fixed images are available.🤖 Prompt for AI Agents