fix(stackable-base): Update expected ca-certificates package name#1351
fix(stackable-base): Update expected ca-certificates package name#1351
Conversation
sbernauer
left a comment
There was a problem hiding this comment.
Just to be sure, you checked trust list --filter=ca-anchors | grep 'E-Tugra'?
Yes I did, it is gone as expected: |
|
Oh nice! In that case I'd say we can remove the entire CVE-2023-37920 handling |
|
Oh yeah, you might be right. I will test this after this PR is merged and will raise a new one if we are sure it is gone. |
|
Works for me 👍 |
|
Okay I just checked if the CA certificates are gone before we update the root trust store via our blocklist. And yes, they are still there. I temporarily removed our blocklist and our check fails: As such, the handling cannot be removed yet and we still need our blocklist to be in place. |
|
Ahh, that makes sense. Thanks for checking |
The
ca-certificatespackages was recently updated and caused pretty much all image builds to fail. This PR updates the expected package name to the actual package name.A local test build of the
stackable-baseimage was successful.