gitops-operator icon indicating copy to clipboard operation
gitops-operator copied to clipboard

[1.13] fix CVE namespace-isolation break CVE-13484

Open anandrkskd opened this issue 10 months ago • 10 comments

argocd adds cluster monitoring label if the ns contains openshift- prefix

What type of PR is this?

/kind bug

What does this PR do / why we need it: This PR fixes the namespace isolation break, caused by using cluster-monitoring label for monitoring Have you updated the necessary documentation?

  • [ ] Documentation update is required by this PR.
  • [ ] Documentation has been updated.

Which issue(s) this PR fixes:

Fixes GITOPS-6251

Test acceptance criteria:

  • [ ] Unit Test
  • [ ] E2E Test

How to test changes / Special notes to the reviewer:

anandrkskd avatar Mar 20 '25 09:03 anandrkskd

/lgtm /approved

iam-veeramalla avatar Mar 21 '25 07:03 iam-veeramalla

/retest

anandrkskd avatar Mar 24 '25 07:03 anandrkskd

/retest

varshab1210 avatar Mar 24 '25 16:03 varshab1210

/retest

anandrkskd avatar Mar 26 '25 05:03 anandrkskd

/lgtm /approve

iam-veeramalla avatar Apr 03 '25 07:04 iam-veeramalla

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: iam-veeramalla

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment Approvers can cancel approval by writing /approve cancel in a comment

openshift-ci[bot] avatar Apr 03 '25 07:04 openshift-ci[bot]

/test v4.14-kuttl-sequential

anandrkskd avatar Apr 03 '25 13:04 anandrkskd

/test v4.14-kuttl-sequential

anandrkskd avatar Apr 04 '25 08:04 anandrkskd

/test v4.14-kuttl-sequential

anandrkskd avatar Apr 04 '25 10:04 anandrkskd

/test v4.14-kuttl-sequential

anandrkskd avatar Apr 08 '25 09:04 anandrkskd

@anandrkskd: The following test failed, say /retest to rerun all failed tests or /retest-required to rerun all mandatory failed tests:

Test name Commit Details Required Rerun command
ci/prow/v4.14-kuttl-sequential 2fa690575d4f834a0f3d562115823a4af3302ba0 link true /test v4.14-kuttl-sequential

Full PR test history. Your PR dashboard.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

openshift-ci[bot] avatar Apr 08 '25 11:04 openshift-ci[bot]

Closing as 1.13 is out of support.

anandrkskd avatar Apr 09 '25 04:04 anandrkskd