[Openstack-security] [Bug 1552182] [NEW] LMA toolchain should alert when packages upgrade is available

Swann Croiset swann at oopss.org
Wed Mar 2 11:09:24 UTC 2016


Public bug reported:

Mainly for security reason, the LMA toolchain should alert when packages
upgrade is highly recommended.

For example, the package nagios-plugins-basic [0] provides  the command:
check_apt

====================================================
root at node-23:~#  /usr/lib/nagios/plugins/check_apt
APT CRITICAL: 3 packages available for upgrade (2 critical updates). |available_upgrades=3;;;0 critical_updates=2;;;0

root at node-23:~# apt-get upgrade
Reading package lists... Done
Building dependency tree       
Reading state information... Done
Calculating upgrade... Done
The following packages will be upgraded:
  libssl1.0.0 openssl
The following packages will be DOWNGRADED:
  python-urllib3
2 upgraded, 0 newly installed, 1 downgraded, 0 to remove and 0 not upgraded.
Need to get 1,443 kB of archives.
After this operation, 124 kB of additional disk space will be used.
Do you want to continue? [Y/n]
====================================================

[0] http://packages.ubuntu.com/trusty/nagios-plugins-basic

** Affects: lma-toolchain
     Importance: Undecided
         Status: New


** Tags: security

** Description changed:

  Mainly for security reason, the LMA toolchain should alert when packages
  upgrade is highly recommended.
  
  For example, the package nagios-plugins-basic [0] provides  the command:
  check_apt
  
+ ====================================================
  root at node-23:~#  /usr/lib/nagios/plugins/check_apt
  APT CRITICAL: 3 packages available for upgrade (2 critical updates). |available_upgrades=3;;;0 critical_updates=2;;;0
  
+ root at node-23:~# apt-get upgrade
+ Reading package lists... Done
+ Building dependency tree       
+ Reading state information... Done
+ Calculating upgrade... Done
+ The following packages will be upgraded:
+   libssl1.0.0 openssl
+ The following packages will be DOWNGRADED:
+   python-urllib3
+ 2 upgraded, 0 newly installed, 1 downgraded, 0 to remove and 0 not upgraded.
+ Need to get 1,443 kB of archives.
+ After this operation, 124 kB of additional disk space will be used.
+ Do you want to continue? [Y/n]
+ ====================================================
  
  [0] http://packages.ubuntu.com/trusty/nagios-plugins-basic

-- 
You received this bug notification because you are a member of OpenStack
Security, which is subscribed to OpenStack.
https://bugs.launchpad.net/bugs/1552182

Title:
  LMA toolchain should alert when packages upgrade is available

Status in LMA Toolchain:
  New

Bug description:
  Mainly for security reason, the LMA toolchain should alert when
  packages upgrade is highly recommended.

  For example, the package nagios-plugins-basic [0] provides  the
  command: check_apt

  ====================================================
  root at node-23:~#  /usr/lib/nagios/plugins/check_apt
  APT CRITICAL: 3 packages available for upgrade (2 critical updates). |available_upgrades=3;;;0 critical_updates=2;;;0

  root at node-23:~# apt-get upgrade
  Reading package lists... Done
  Building dependency tree       
  Reading state information... Done
  Calculating upgrade... Done
  The following packages will be upgraded:
    libssl1.0.0 openssl
  The following packages will be DOWNGRADED:
    python-urllib3
  2 upgraded, 0 newly installed, 1 downgraded, 0 to remove and 0 not upgraded.
  Need to get 1,443 kB of archives.
  After this operation, 124 kB of additional disk space will be used.
  Do you want to continue? [Y/n]
  ====================================================

  [0] http://packages.ubuntu.com/trusty/nagios-plugins-basic

To manage notifications about this bug go to:
https://bugs.launchpad.net/lma-toolchain/+bug/1552182/+subscriptions




More information about the Openstack-security mailing list