Skip to content

Conversation

@polmoorx
Copy link
Contributor

@polmoorx polmoorx commented Dec 4, 2025

Merge Checklist

All boxes should be checked before merging the PR

  • The changes in the PR have been built and tested
  • cgmanifest file has been updated if required
  • Ready to merge

Description

Any Newly Introduced Dependencies

No

How Has This Been Tested?

Manually tested.

@polmoorx polmoorx requested a review from a team as a code owner December 4, 2025 09:52
@polmoorx polmoorx force-pushed the upgrade-rpc-version-to-fix-cve branch from d145ab3 to c131f11 Compare December 4, 2025 14:07
@polmoorx polmoorx force-pushed the upgrade-rpc-version-to-fix-cve branch 2 times, most recently from 90f9ed3 to 1313923 Compare December 5, 2025 09:30
@aaroncyew aaroncyew added the rpc label Dec 5, 2025
@aaroncyew
Copy link
Member

Automated Messages: Label 'rpc' has been added to this Pull Request.

Copy link
Contributor

@andy-vm andy-vm left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

please also share rpm build result

@polmoorx polmoorx force-pushed the upgrade-rpc-version-to-fix-cve branch 2 times, most recently from f42601b to 44d3c3f Compare December 9, 2025 08:33
@polmoorx
Copy link
Contributor Author

polmoorx commented Dec 9, 2025

please also share rpm build result

I ran the Jenkins delta build, and no issues were observed.
For your reference, please see the build result under Build #1365.

@polmoorx polmoorx force-pushed the upgrade-rpc-version-to-fix-cve branch from 44d3c3f to e41267e Compare December 10, 2025 15:08
@andy-vm andy-vm self-requested a review December 11, 2025 03:20
andy-vm
andy-vm previously approved these changes Dec 11, 2025
Copy link
Contributor

@andy-vm andy-vm left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@polmoorx polmoorx force-pushed the upgrade-rpc-version-to-fix-cve branch from e41267e to 8bb2491 Compare December 12, 2025 04:39
- Upgraded the RPC from 2.45.1 to 2.48.9 to resolve the
  CVE-2025-47914, CVE-2025-58181 and CVE-2025-47913.

- Update the rpc.spec file with release, dump version and changelog entry.

Signed-off-by: Polmoorx Shiva Kumar <polmoorx.shiva.kumar@intel.com>
@polmoorx polmoorx force-pushed the upgrade-rpc-version-to-fix-cve branch from 8bb2491 to 474d9e6 Compare December 12, 2025 05:45
@polmoorx polmoorx changed the title Upgrade the RPC component version from 2.45.1 to 2.48.9 Upgrade the RPC version from 2.45.1 to 2.48.9 Dec 12, 2025
@cheeyanglee cheeyanglee merged commit 8bb17e9 into open-edge-platform:3.0-dev Dec 12, 2025
14 of 18 checks passed
cheeyanglee pushed a commit to cheeyanglee/edge-microvisor-toolkit that referenced this pull request Jan 22, 2026
- Upgraded the RPC from 2.45.1 to 2.48.9 to resolve the
  CVE-2025-47914, CVE-2025-58181 and CVE-2025-47913.

- Update the rpc.spec file with release, dump version and changelog entry.

Signed-off-by: Polmoorx Shiva Kumar <polmoorx.shiva.kumar@intel.com>
cheeyanglee added a commit that referenced this pull request Jan 23, 2026
* ip4save config change (#620)

* Update full.json

Added ip4save changes for iso

* Create configure-ip4save.sh

Post installation script for iso to allow type 8 incoming ping

* Separated post installation paths in full.json

* Fixed file permission for configure-ip4save.sh

* Fixed indentation for full.json

---------

Co-authored-by: andy-vm <108446482+andy-vm@users.noreply.github.com>
Co-authored-by: Mohamad Noor Alim Hussin <mohamad.noor.alim.hussin@intel.com>

* Upgrade otelcol-contrib version to fix CVE. (#623)

- Upgrade version to 0.141.0.
 - Remove CVE-2025-22872.patch since changes are part of latest version.
 - Fixes CVE-2025-47913, CVE-2025-47914 and CVE-2025-58181.

Signed-off-by: Unniche, BasavarajX <basavarajx.unniche@intel.com>
Co-authored-by: andy-vm <108446482+andy-vm@users.noreply.github.com>

* Upgrade the RPC version from 2.45.1 to 2.48.9 (#619)

- Upgraded the RPC from 2.45.1 to 2.48.9 to resolve the
  CVE-2025-47914, CVE-2025-58181 and CVE-2025-47913.

- Update the rpc.spec file with release, dump version and changelog entry.

Signed-off-by: Polmoorx Shiva Kumar <polmoorx.shiva.kumar@intel.com>

* restore caddy (#642)

* restore caddy

* restore caddy

---------

Co-authored-by: andy.peng <andypeng@pglgull002.png.intel.com>
Signed-off-by: Lee Chee Yang <chee.yang.lee@intel.com>

* CVE Fix for x-crypto component in caddy (#672)

- Applied suggested patch from NVD database for
 - CVE-2025-58181.

Signed-off-by: Unniche, BasavarajX <basavarajx.unniche@intel.com>
Co-authored-by: andy-vm <108446482+andy-vm@users.noreply.github.com>

* Removed go-rpm-macros dependency in caddy.spec (#689)

* Update CVE patches to fix CVE issues (#661)

- Include fix for CVE-2025-61727 and CVE-2025-61729.

- Updated caddy.spec file to update release,
  bump version, and add changelog entries.

Signed-off-by: Polmoorx Shiva Kumar <polmoorx.shiva.kumar@intel.com>

---------

Signed-off-by: Unniche, BasavarajX <basavarajx.unniche@intel.com>
Signed-off-by: Polmoorx Shiva Kumar <polmoorx.shiva.kumar@intel.com>
Signed-off-by: Lee Chee Yang <chee.yang.lee@intel.com>
Co-authored-by: chrngc <149708414+chrngc@users.noreply.github.com>
Co-authored-by: andy-vm <108446482+andy-vm@users.noreply.github.com>
Co-authored-by: Mohamad Noor Alim Hussin <mohamad.noor.alim.hussin@intel.com>
Co-authored-by: bunnichx <101382885+bunnichx@users.noreply.github.com>
Co-authored-by: POLMOOR SHIVA KUMAR <polmoorx.shiva.kumar@intel.com>
Co-authored-by: andy.peng <andypeng@pglgull002.png.intel.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants