From a874de6213c5958e34415a9955671a9dc7776f02 Mon Sep 17 00:00:00 2001 From: Tao Li Date: Mon, 31 Aug 2026 16:11:13 +0800 Subject: [PATCH 1/3] chore(dept): bump barman version to 3.20.0 Signed-off-by: Tao Li --- containers/sidecar-requirements.in | 4 ++-- containers/sidecar-requirements.txt | 10 +++++----- 2 files changed, 7 insertions(+), 7 deletions(-) diff --git a/containers/sidecar-requirements.in b/containers/sidecar-requirements.in index 2f84b93..fb1573e 100644 --- a/containers/sidecar-requirements.in +++ b/containers/sidecar-requirements.in @@ -1,2 +1,2 @@ -barman[azure,cloud,google,snappy,zstandard,lz4]==3.19.1 -zipp>=3.19.1 # not directly required, pinned by Snyk to avoid a vulnerability +barman[azure,cloud,google,snappy,zstandard,lz4]==3.20.0 +zipp>=3.20.0 # not directly required, pinned by Snyk to avoid a vulnerability diff --git a/containers/sidecar-requirements.txt b/containers/sidecar-requirements.txt index fcad905..63e541b 100644 --- a/containers/sidecar-requirements.txt +++ b/containers/sidecar-requirements.txt @@ -1,8 +1,8 @@ # -# This file is autogenerated by pip-compile with Python 3.13 +# This file is autogenerated by pip-compile with Python 3.12 # by the following command: # -# pip-compile --allow-unsafe --generate-hashes --no-index --output-file=sidecar-requirements.txt --strip-extras sidecar-requirements.in +# pip-compile --allow-unsafe --generate-hashes --output-file=sidecar-requirements.txt --strip-extras sidecar-requirements.in # azure-core==1.41.0 \ --hash=sha256:522b4011e8180b1a3dcd2024396a4e7fe9ac37fb8597db47163d230b5efe892d \ @@ -18,9 +18,9 @@ azure-storage-blob==12.30.0 \ --hash=sha256:2cd74d4d5731e5eb6b8d5c5056ee115a5e88f8fdf22517b739836fda685018be \ --hash=sha256:d415ac50b67a8da6b3ae7e9f1014b1b55cd7aafa0b8d4ca9b380568dc7360423 # via barman -barman==3.19.1 \ - --hash=sha256:0a6a9e1babf97687732d8b2a3eb79ea95d55246a5257b9433865cb6e755221c0 \ - --hash=sha256:2f71c4a1f1ba53f694cbdf838bb9906d8ba02b97d1fd3041196e8999bec7a1ee +barman==3.20.0 \ + --hash=sha256:02dd8936e62c1829c78597eefedfcab0aa820f5618da2871f38b5bc684891a54 \ + --hash=sha256:1aa92df452f39c357d6547fd0abd3885a8c243ea95002e6fc0b7f66f8e8c24d5 # via -r sidecar-requirements.in boto3==1.43.81 \ --hash=sha256:62ecf695088e06f37500d6cc49a240dc1331379bd5ae992d185fef212038ca29 \ From 585be09c705bf64fad5af2d53b5ecdd3ccea9664 Mon Sep 17 00:00:00 2001 From: Tao Li Date: Mon, 31 Aug 2026 16:38:23 +0800 Subject: [PATCH 2/3] chore(dept): Apply suggestion from @mnencia Co-authored-by: Marco Nenciarini Signed-off-by: Tao Li --- containers/sidecar-requirements.in | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/containers/sidecar-requirements.in b/containers/sidecar-requirements.in index fb1573e..0c8b976 100644 --- a/containers/sidecar-requirements.in +++ b/containers/sidecar-requirements.in @@ -1,2 +1,2 @@ barman[azure,cloud,google,snappy,zstandard,lz4]==3.20.0 -zipp>=3.20.0 # not directly required, pinned by Snyk to avoid a vulnerability +zipp>=3.19.1 # not directly required, pinned by Snyk to avoid a vulnerability From 3d96b6ba0c6b7917d79dae4f98093bca47c9610f Mon Sep 17 00:00:00 2001 From: Tao Li Date: Mon, 31 Aug 2026 21:04:10 +0800 Subject: [PATCH 3/3] chores(dept): includes tar into sidecar image Signed-off-by: Tao Li --- containers/Dockerfile.sidecar | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/containers/Dockerfile.sidecar b/containers/Dockerfile.sidecar index bc7678f..de05de5 100644 --- a/containers/Dockerfile.sidecar +++ b/containers/Dockerfile.sidecar @@ -76,7 +76,7 @@ RUN mkdir -p /dependencies /build/downloads && \ $DISTROLESS_PACKAGES 2>/dev/null | grep "^\w" | sort -u > /tmp/distroless.txt && \ apt-cache depends --recurse --no-recommends --no-suggests \ --no-conflicts --no-breaks --no-replaces --no-enhances \ - libpq5 liblz4-1 libsnappy1v5 2>/dev/null | grep "^\w" | sort -u | \ + libpq5 liblz4-1 libsnappy1v5 tar 2>/dev/null | grep "^\w" | sort -u | \ grep -v -F -x -f /tmp/distroless.txt > /tmp/packages.txt && \ apt-get download $(cat /tmp/packages.txt) && \ for deb in *.deb; do \ @@ -102,6 +102,7 @@ LABEL summary="$SUMMARY" \ COPY --from=pythonbuilder /venv /venv COPY --from=pythonbuilder /dependencies/usr/lib /usr/lib +COPY --from=pythonbuilder /dependencies/usr/bin/tar /usr/bin/tar COPY --from=gobuilder /workspace/manager /manager # Compile all Python bytecode as root to avoid runtime compilation