Skip to content

Fix: Include FIPS-updates repo in security source list (#337)#338

Open
Rkoffer-SMX wants to merge 1 commit into
Azure:masterfrom
Rkoffer-SMX:fix/fips-updates-security-filter
Open

Fix: Include FIPS-updates repo in security source list (#337)#338
Rkoffer-SMX wants to merge 1 commit into
Azure:masterfrom
Rkoffer-SMX:fix/fips-updates-security-filter

Conversation

@Rkoffer-SMX
Copy link
Copy Markdown

The security source list filter excluded FIPS-updates repos because they use suite names like "jammy-updates" instead of "jammy-security". This caused apt to resolve packages from jammy-security during installation, replacing FIPS-certified packages with non-FIPS versions.

Broadens the filter in both one-line and DEB882-style source list readers to also retain lines/stanzas containing "fips-updates".

The security source list filter excluded FIPS-updates repos because they
use suite names like "jammy-updates" instead of "jammy-security". This
caused apt to resolve packages from jammy-security during installation,
replacing FIPS-certified packages with non-FIPS versions.

Broadens the filter in both one-line and DEB882-style source list
readers to also retain lines/stanzas containing "fips-updates".
@Rkoffer-SMX
Copy link
Copy Markdown
Author

@microsoft-github-policy-service agree company="SMX"

Comment thread src/core/src/package_managers/AptitudePackageManager.py
@kjohn-msft kjohn-msft enabled auto-merge (squash) May 6, 2026 23:38
yashnap added a commit that referenced this pull request Jun 3, 2026
Refer to the old PR :
#338 for more
Information.
Created PR because the original PR was lacking essentials checks :
Suspicion is that since it was created from fork it didn't run essential
checks marking it as unable to merge.

Proof Test:

**Failing** 
Created PR from my fork :
#349
- It fails on Upload coverage to Codecov step :
https://github.com/Azure/LinuxPatchExtension/actions/runs/26290421614/job/77388883207?pr=349
with the below error
<img width="1396" height="407" alt="notoken"
src="https://github.com/user-attachments/assets/d74cdcce-ff8e-4d7d-848d-c3591224e0fb"
/>

**Success**
For successful PR :
https://github.com/Azure/LinuxPatchExtension/actions/runs/26258749218/job/77287296261?pr=348
<img width="1436" height="483" alt="tokenfound"
src="https://github.com/user-attachments/assets/fb133c86-7efb-41d1-8584-7057563da57a"
/>

Plausible reason: It is failing to get the Codecov secret Token when run
from fork : CODECOV_TOKEN: ${{ secrets.CODECOV_TOKEN }}
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants