SUSE-RU-2022:4502-1: moderate: Recommended update for rekor

sle-updates at lists.suse.com sle-updates at lists.suse.com
Fri Dec 16 11:19:52 UTC 2022


   SUSE Recommended Update: Recommended update for rekor
______________________________________________________________________________

Announcement ID:    SUSE-RU-2022:4502-1
Rating:             moderate
References:         SLE-23476 
Affected Products:
                    SUSE Linux Enterprise Desktop 15-SP4
                    SUSE Linux Enterprise High Performance Computing 15-SP4
                    SUSE Linux Enterprise Module for Basesystem 15-SP4
                    SUSE Linux Enterprise Server 15-SP4
                    SUSE Linux Enterprise Server for SAP Applications 15-SP4
                    SUSE Manager Proxy 4.3
                    SUSE Manager Retail Branch Server 4.3
                    SUSE Manager Server 4.3
                    openSUSE Leap 15.4
______________________________________________________________________________

   An update that has 0 recommended fixes and contains one
   feature can now be installed.

Description:

   This update for rekor fixes the following issues:

   Rekor was updated to 1.0.1 (jsc#SLE-23476):

   - stop inserting envelope hash for intoto:0.0.2 types into index

   - build with FIPSified go1.18.

   updated to rekor 1.0.0 (jsc#SLE-23476):

   - add description on /api/v1/index/retrieve endpoint
   - Adding e2e test coverage
   - export rekor build/version information
   - Use POST instead of GET for /api/log/entries/retrieve metrics.
   - Search through all shards when searching
   - verify: verify checkpoint's STH against the inclusion proof root hash
   - add ability to enable/disable specific rekor API endpoints
   - enable configurable client retries with backoff in RekorClient
   - remove dead code around api-key and timestamp references
   - update swagger API version to 1.0.0
   - remove unused RekorVersion API definition
   - install gocovmerge in hack/tools
   - add retry command line flag on rekor-cli
   - Add some info and debug logging to commonly used funcs

   updated to rekor 0.12.2 (jsc#SLE-23476):

   - add description on /api/v1/index/retrieve endpoint
   - Adding e2e test coverage
   - export rekor build/version information
   - Use POST instead of GET for /api/log/entries/retrieve metrics.
   - Search through all shards when searching by hash

   updated to rekor 0.12.1 (jsc#SLE-23476):

   - ** Rekor ** v0.12.1 comes with a breaking change to rekor-cli v0.12.1.
     Users of rekor-cli MUST upgrade to the latest version The addition of
     the intotov2 created a breaking change for the rekor-cli

   - What's Changed

     - fix: fix harness tests with intoto v0.0.2
     - feat: add file based signer and password
     - Adds new rekor metrics for latency and QPS.


Patch Instructions:

   To install this SUSE Recommended Update use the SUSE recommended installation methods
   like YaST online_update or "zypper patch".

   Alternatively you can run the command listed for your product:

   - openSUSE Leap 15.4:

      zypper in -t patch openSUSE-SLE-15.4-2022-4502=1

   - SUSE Linux Enterprise Module for Basesystem 15-SP4:

      zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP4-2022-4502=1



Package List:

   - openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64):

      rekor-1.0.1-150400.4.6.1

   - SUSE Linux Enterprise Module for Basesystem 15-SP4 (aarch64 ppc64le s390x x86_64):

      rekor-1.0.1-150400.4.6.1


References:




More information about the sle-updates mailing list