Skip to content

build(deps): bump postgres 18.4 -> 18.6 and oauth2-proxy to v7.15.5 - #9198

Open
DoDiODev wants to merge 1 commit into
apache:mainfrom
DoDiODev:pr/wave11-container-images
Open

DoDiODev wants to merge 1 commit into
apache:mainfrom
DoDiODev:pr/wave11-container-images

Conversation

@DoDiODev

@DoDiODev DoDiODev commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

Summary

Dependabot (#9099) already moved backend/test/e2e/remote/docker-compose.test.yml to postgres:18.6-alpine, but it cannot see the remaining pins: the docker-compose-dev-*.yml file names do not match its compose filename pattern, and the github-actions ecosystem only reads uses:, not services: images. This PR brings those remaining pins in line.

Changes

File Image From To
docker-compose-dev-postgresql.yml postgres 18.4 18.6
.github/workflows/test-e2e.yml (e2e-postgres service) postgres 18.4 18.6
docker-compose-dev-mysql.yml, docker-compose-dev-postgresql.yml quay.io/oauth2-proxy/oauth2-proxy v7.15.3-amd64 v7.15.5-amd64

oauth2-proxy v7.15.5 fixes two critical authentication bypasses (GHSA-63jm-59jj-478j, GHSA-wr5q-7wxw-x568) and a moderate credential disclosure (GHSA-hhqp-vx7f-5c6m), plus the CVE fixes of v7.15.4. Its stricter handling of --skip-auth-route/--skip-auth-regex and X-Forwarded-Uri only matters for deployments that configure those options; the dev compose files configure the proxy solely via .env and set none of them. PostgreSQL 18.6 is a minor (bug-fix/security) release within 18.x, so no dump/restore is needed.

No Go/Python/TypeScript source, lock file or devops/releases/** change.

Verification

Check Result
docker compose -f docker-compose-dev-{mysql,postgresql}.yml config -q ✅
docker manifest inspect for both new tags ✅
Unmodified upstream workflows in the fork on top of current main ✅ all 9 green, incl. e2e-postgres (log shows postgres:18.6), e2e-mysql and test

Dependabot (apache#9099) already moved the remote e2e compose file to
`postgres:18.6-alpine`, but it cannot see the remaining pins:
`docker-compose-dev-*.yml` does not match its compose filename pattern
and the `github-actions` ecosystem ignores workflow `services:` images.

- `postgres` 18.4 -> 18.6 in `docker-compose-dev-postgresql.yml` and the
  `e2e-postgres` service of `.github/workflows/test-e2e.yml`.
- `oauth2-proxy` v7.15.3 -> v7.15.5 (`-amd64` tag kept) in both dev
  compose files. v7.15.5 fixes two critical authentication bypasses
  (GHSA-63jm-59jj-478j, GHSA-wr5q-7wxw-x568) and a moderate credential
  disclosure (GHSA-hhqp-vx7f-5c6m).
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant