Skip to content

build(deps): bump postgres 18.4 -> 18.6 and oauth2-proxy to v7.15.5 - #9198

Merged
klesh merged 1 commit into
apache:mainfrom
DoDiODev:pr/wave11-container-images
Oct 8, 2026
Merged

klesh merged 1 commit into
apache:mainfrom
DoDiODev:pr/wave11-container-images

Conversation

@DoDiODev

@DoDiODev DoDiODev commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

Summary

Dependabot (#9099) already moved backend/test/e2e/remote/docker-compose.test.yml to postgres:18.6-alpine, but it cannot see the remaining pins: the docker-compose-dev-*.yml file names do not match its compose filename pattern, and the github-actions ecosystem only reads uses:, not services: images. This PR brings those remaining pins in line.

Changes

File Image From To
docker-compose-dev-postgresql.yml postgres 18.4 18.6
.github/workflows/test-e2e.yml (e2e-postgres service) postgres 18.4 18.6
docker-compose-dev-mysql.yml, docker-compose-dev-postgresql.yml quay.io/oauth2-proxy/oauth2-proxy v7.15.3-amd64 v7.15.5-amd64

oauth2-proxy v7.15.5 fixes two critical authentication bypasses (GHSA-63jm-59jj-478j, GHSA-wr5q-7wxw-x568) and a moderate credential disclosure (GHSA-hhqp-vx7f-5c6m), plus the CVE fixes of v7.15.4. Its stricter handling of --skip-auth-route/--skip-auth-regex and X-Forwarded-Uri only matters for deployments that configure those options; the dev compose files configure the proxy solely via .env and set none of them. PostgreSQL 18.6 is a minor (bug-fix/security) release within 18.x, so no dump/restore is needed.

No Go/Python/TypeScript source, lock file or devops/releases/** change.

Verification

Check Result
docker compose -f docker-compose-dev-{mysql,postgresql}.yml config -q ✅
docker manifest inspect for both new tags ✅
Unmodified upstream workflows in the fork on top of current main ✅ all 9 green, incl. e2e-postgres (log shows postgres:18.6), e2e-mysql and test

Dependabot (apache#9099) already moved the remote e2e compose file to
`postgres:18.6-alpine`, but it cannot see the remaining pins:
`docker-compose-dev-*.yml` does not match its compose filename pattern
and the `github-actions` ecosystem ignores workflow `services:` images.

- `postgres` 18.4 -> 18.6 in `docker-compose-dev-postgresql.yml` and the
  `e2e-postgres` service of `.github/workflows/test-e2e.yml`.
- `oauth2-proxy` v7.15.3 -> v7.15.5 (`-amd64` tag kept) in both dev
  compose files. v7.15.5 fixes two critical authentication bypasses
  (GHSA-63jm-59jj-478j, GHSA-wr5q-7wxw-x568) and a moderate credential
  disclosure (GHSA-hhqp-vx7f-5c6m).
@klesh
klesh merged commit 9b71603 into apache:main Oct 8, 2026
10 checks passed
@DoDiODev
DoDiODev deleted the pr/wave11-container-images branch October 8, 2026 13:37
DoDiODev added a commit to DoDiODev/devlake that referenced this pull request Oct 8, 2026
Mirror checkout v7 / cache v6 (apache#9105), super-linter v7 (apache#9184), the go mod tidy guard (apache#9179) and postgres 18.6 (apache#9198); workflow-sync is green again. Drop the outdated wave-6 and Go 1.26.2 remarks.

Signed-off-by: DoDiODev <DoDiDev@proton.me>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants