Skip to content

Bump base images for v1.29.6.1 security release#324

Merged
prathyushpv merged 1 commit into
release/v1.29.xfrom
bump-base-images-1.15.22
May 6, 2026
Merged

Bump base images for v1.29.6.1 security release#324
prathyushpv merged 1 commit into
release/v1.29.xfrom
bump-base-images-1.15.22

Conversation

@prathyushpv
Copy link
Copy Markdown

@prathyushpv prathyushpv commented May 6, 2026

Update BASE_SERVER_IMAGE and BASE_ADMIN_TOOLS_IMAGE references on release/v1.29.x to pick up Alpine package updates (notably nghttp2-libs 1.68.0 → 1.68.1, fixing CVE-2026-27135 High).

Why

v1.29.6 production image flags nghttp2-libs High in Grype.

Verification

  • temporalio/base-server:1.15.22 — Grype: 0 vulnerabilities
  • temporalio/base-admin-tools:1.12.21 — Grype: 0 vulnerabilities

@prathyushpv prathyushpv requested a review from a team as a code owner May 6, 2026 20:20
@prathyushpv prathyushpv merged commit 76f8bfe into release/v1.29.x May 6, 2026
8 checks passed
@prathyushpv prathyushpv deleted the bump-base-images-1.15.22 branch May 6, 2026 20:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants