Skip to content

Update Minio container image#29092

Open
mosabua wants to merge 1 commit intotrinodb:masterfrom
simpligility:minioupdate
Open

Update Minio container image#29092
mosabua wants to merge 1 commit intotrinodb:masterfrom
simpligility:minioupdate

Conversation

@mosabua
Copy link
Copy Markdown
Member

@mosabua mosabua commented Apr 13, 2026

Description

Addresses CVE-2026-39414 (GHSA-h749-fxx7-pwpg) in the older image.

Additional context and related issues

This is now using the Chainguard EmeritOSS maintained version of MinIO, which now includes patches for security issues.

Uses https://github.com/chainguard-forks/minio/releases/tag/RELEASE.2026-04-10T21-52-59Z

Related PR for aws-proxy is at trinodb/aws-proxy#210

Release notes

(x) This is not user-visible or is docs only, and no release notes are required.

@cla-bot cla-bot Bot added the cla-signed label Apr 13, 2026
ebyhr
ebyhr previously approved these changes Apr 13, 2026
@mosabua mosabua force-pushed the minioupdate branch 2 times, most recently from c279ba4 to 28d7596 Compare April 13, 2026 20:40
@mosabua
Copy link
Copy Markdown
Member Author

mosabua commented Apr 13, 2026

Should this not run more tests @ebyhr ?

@mosabua
Copy link
Copy Markdown
Member Author

mosabua commented Apr 13, 2026

Haha .. now it suddenly kicked things off .. thanks @ebyhr

@mosabua
Copy link
Copy Markdown
Member Author

mosabua commented Apr 13, 2026

Test failure looks like a false alarm to me. Thoughts @ebyhr @wendigo @electrum ?

@ebyhr ebyhr dismissed their stale review April 13, 2026 22:05

TestDeltaLakeOssDeltaLakeMinioReads is broken now.

@mosabua
Copy link
Copy Markdown
Member Author

mosabua commented Apr 13, 2026

Whoa .. this is weird. Earlier run everything passed apart from the referenced Delta Lake test .. now Iceberg with minio-avro is also busting out .. will see how this continues.

@findepi
Copy link
Copy Markdown
Member

findepi commented Apr 14, 2026

Addresses CVE-2026-39414 (GHSA-h749-fxx7-pwpg) in the older image.

Does this matter?
it's tests.

@mosabua
Copy link
Copy Markdown
Member Author

mosabua commented Apr 15, 2026

Addresses CVE-2026-39414 (GHSA-h749-fxx7-pwpg) in the older image.

Does this matter? it's tests.

Ideally we update since these tests also run on CI/CD and developer machines, but we would have to find out why the tests are failing first. I am not sure when I can get into the details.

@github-actions
Copy link
Copy Markdown

github-actions Bot commented May 6, 2026

This pull request has gone a while without any activity. Ask for help on #core-dev on Trino slack.

@github-actions github-actions Bot added the stale label May 6, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Development

Successfully merging this pull request may close these issues.

3 participants