Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[kube-prometheus-stack]: bump grafana chart dependency to 6.45.0 and node-exporter to 4.8.0 #2773

Merged
merged 2 commits into from
Dec 4, 2022

Conversation

stevo-f3
Copy link
Contributor

@stevo-f3 stevo-f3 commented Dec 2, 2022

Signed-off-by: Stevo Slavić [email protected]

What this PR does / why we need it

This PR updates Grafana Helm chart dependency in kube-prometheus-stack Helm chart to help address a security vulnerability. Namely a new version (9.3.0) of Grafana has been released fixing a critical vulnerability and more. Grafana Helm chart version 6.44.11 has been released with the Grafana 9.3.0 update (see grafana/helm-charts#2033). This PR updates to the latest Grafana Helm chart.

In the same go prometheus-node-exporter chart is being bumped to 4.8.0, with among other things node-exporter binary bumped from 1.3.1 to 1.5.0 addressing multiple CVEs and a workaround prometheus/node_exporter#2530 for a kernel race condition prometheus/node_exporter#2500.

Which issue this PR fixes

(optional, in fixes #<issue number>(, fixes #<issue_number>, ...) format, will close that issue when PR gets merged)

  • fixes #

Special notes for your reviewer

Checklist

  • DCO signed
  • Chart Version bumped
  • Title of the PR starts with chart name (e.g. [prometheus-couchdb-exporter])

@stevo-f3
Copy link
Contributor Author

stevo-f3 commented Dec 2, 2022

cc @monotek since vulnerability

@stevo-f3 stevo-f3 changed the title [kube-prometheus-stack]: bump grafana chart dependency to 6.44.11 and node-exporter to 4.8.0 [kube-prometheus-stack]: bump grafana chart dependency to 6.45.0 and node-exporter to 4.8.0 Dec 3, 2022
@monotek monotek merged commit 8b4c793 into prometheus-community:main Dec 4, 2022
@nourspace
Copy link
Contributor

Thank you sir @stevo-f3

stamzid pushed a commit to Unstructured-IO/prometheus-community-helm-charts that referenced this pull request Mar 3, 2023
…node-exporter to 4.8.0 (prometheus-community#2773)

Signed-off-by: Stevo Slavić <[email protected]>

Signed-off-by: Stevo Slavić <[email protected]>
Co-authored-by: MH <[email protected]>
Matiasmct pushed a commit to giffgaff/prometheus-charts-backup that referenced this pull request May 16, 2023
…node-exporter to 4.8.0 (prometheus-community#2773)

Signed-off-by: Stevo Slavić <[email protected]>

Signed-off-by: Stevo Slavić <[email protected]>
Co-authored-by: MH <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants