Skip to content

fix(deps): update build-tools for CVE remediation - #355

Merged
karelhala merged 1 commit into
RedHatInsights:masterfrom
platex-rehor-bot:bot/RHCLOUD-49932
Aug 4, 2026
Merged

fix(deps): update build-tools for CVE remediation#355
karelhala merged 1 commit into
RedHatInsights:masterfrom
platex-rehor-bot:bot/RHCLOUD-49932

Conversation

@platex-rehor-bot

@platex-rehor-bot platex-rehor-bot commented Aug 4, 2026

Copy link
Copy Markdown
Contributor

Description

Update the build-tools submodule (insights-frontend-builder-common) to the latest version to address container image CVEs flagged in the GovCloud compliance scan.

RHCLOUD-49932

What changed:

  • build-tools submodule updated from d7be112 to 4ba1f7e
  • UBI9 Node.js builder image bumped from 9.7-1778648048 to 9.8-1780375952
  • Rebuild will pull latest caddy-ubi:latest runtime image

CVE coverage:


Anything reviewers should know?

This is a submodule-only change — no application source code is modified. All 110 unit tests pass. The existing mintmaker PR #328 targets the same submodule update but has merge conflicts; this PR provides a clean version from current master.


Checklist

  • Accessibility: color contrast, keyboard nav, screen reader tested (or N/A)
  • All PR checks pass locally (build, lint, test)
  • No unrelated changes included
  • (Optional) QE: OUIA changed, test impact, no coverage
  • (Optional) UX: end-user UX modified, designs need sign-off

AI disclosure

Assisted by: Claude Code

RHCLOUD-49932
Update insights-frontend-builder-common submodule from d7be112 to 4ba1f7e.
This bumps the UBI9 Node.js builder image from 9.7 to 9.8, pulling in
newer RPM packages that address fixable CVEs (glib2, libacl, glibc,
libsolv). The caddy-ubi runtime image uses :latest tag, so a rebuild
will also pull the latest caddy-ubi with updated Go dependencies.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Aug 4, 2026

Copy link
Copy Markdown

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 1c64ff5d-3bbe-4c21-9c74-c7c471edafab

📥 Commits

Reviewing files that changed from the base of the PR and between 76e86f5 and cb22001.

📒 Files selected for processing (1)
  • build-tools

Summary by CodeRabbit

  • Chores
    • Updated the build tooling to a newer revision.
    • No user-facing functionality or public API changes.

Walkthrough

The build-tools submodule reference changes from commit d7be1120600804f9c02a7327e4bc510d1c57cd27 to commit 4ba1f7eeadd1cab58c17ef8201286340b230bcba.

Changes

Build tools update

Layer / File(s) Summary
Update submodule pointer
build-tools
The submodule reference points to commit 4ba1f7eeadd1cab58c17ef8201286340b230bcba.

Estimated code review effort: 1 (Trivial) | ~2 minutes

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly identifies the build-tools dependency update and its CVE remediation purpose.
Description check ✅ Passed The description explains the submodule update, CVE remediation, testing, issue reference, reviewer notes, checklist, and AI disclosure.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@karelhala
karelhala merged commit 143f64f into RedHatInsights:master Aug 4, 2026
9 checks passed
@platex-rehor-bot
platex-rehor-bot deleted the bot/RHCLOUD-49932 branch August 4, 2026 10:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants