Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Remove the old tekton version #2772

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

hansinikarunarathne
Copy link
Member

Pull Request Template for Kubeflow manifests Issues

  • Please include a summary of changes and the related issue.
  • List any dependencies that are required for this change.
  • Please delete the options that are not relevant.
  • The following checklist will help you to satisfy the requirements.

✏️ A brief description of the changes

Deleted the /https://github.com/kubeflow/manifests/tree/master/apps/kfp-tekton/upstream folder and https://github.com/kubeflow/manifests/blob/master/.github/issue_label_bot.yaml yaml file

🐛 If this PR is related to an issue, please put the link of the issue here.

#2765

✅ Contributor checklist


You can join the CNCF Slack and access our meetings at the Kubeflow Community website. Our channel on the CNCF Slack is here #kubeflow-platform.

@juliusvonkohout
Copy link
Member

@rimolive can you review this, because you are actively working on the tekton merge?

@juliusvonkohout juliusvonkohout self-assigned this Jul 2, 2024
@juliusvonkohout juliusvonkohout linked an issue Jul 30, 2024 that may be closed by this pull request
7 tasks
@juliusvonkohout
Copy link
Member

@rimolive do you have any concerns?

@rimolive
Copy link
Member

rimolive commented Aug 1, 2024

My advice is to not remove yet. I don't think we had the kfp manifests prepared to use argo or tekton as backend, and these manifests are the reference.

Let's see who will continue the kfp-tekton merge work and let them know this manifest work is missing.

@juliusvonkohout
Copy link
Member

alright then lets close for now and focus on something else.

@juliusvonkohout
Copy link
Member

@rimolive either we get a new kfp-tekton release (https://github.com/kubeflow/manifests/blob/2269c67372dd4664edf5faae9eb80d90db2ae7d0/hack/sync-kfp-tekton-manifests.sh) or we have to remove the separate 2.0.5 kfptekton from the manifests since it add many CVEs and seems to be abandoned.

Copy link

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by:
Once this PR has been reviewed and has the lgtm label, please ask for approval from juliusvonkohout. For more information see the Kubernetes Code Review Process.

The full list of commands accepted by this bot can be found here.

Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@juliusvonkohout
Copy link
Member

See also #2856

@hansinikarunarathne please rebase or create a new PR for this.

@juliusvonkohout
Copy link
Member

Even in this excerpt the differences are massive

Scanning  gcr.io/ml-pipeline/api-server:2.0.5
+----------+------+--------+-----+
| Critical | High | Medium | Low |
+----------+------+--------+-----+
|    3     |  36  |   76   |  65 |
+----------+------+--------+-----+
Scanning  gcr.io/ml-pipeline/api-server:2.2.0
+----------+------+--------+-----+
| Critical | High | Medium | Low |
+----------+------+--------+-----+
|    3     |  14  |   62   |  63 |
+----------+------+--------+-----+
Scanning  gcr.io/ml-pipeline/application-crd-controller:20231101
+----------+------+--------+-----+
| Critical | High | Medium | Low |
+----------+------+--------+-----+
|    1     |  13  |   19   |  0  |
+----------+------+--------+-----+
Scanning  gcr.io/ml-pipeline/cache-deployer:2.2.0
+----------+------+--------+-----+
| Critical | High | Medium | Low |
+----------+------+--------+-----+
|    13    |  23  |   77   |  2  |
+----------+------+--------+-----+
Scanning  gcr.io/ml-pipeline/cache-server:2.2.0
+----------+------+--------+-----+
| Critical | High | Medium | Low |
+----------+------+--------+-----+
|    1     |  7   |   44   |  6  |
+----------+------+--------+-----+
Scanning  gcr.io/ml-pipeline/frontend:2.0.5
+----------+------+--------+-----+
| Critical | High | Medium | Low |
+----------+------+--------+-----+
|    4     |  36  |   62   |  10 |
+----------+------+--------+-----+
Scanning  gcr.io/ml-pipeline/frontend:2.2.0
+----------+------+--------+-----+
| Critical | High | Medium | Low |
+----------+------+--------+-----+
|    4     |  35  |   57   |  10 |
+----------+------+--------+-----+
Scanning  gcr.io/ml-pipeline/inverse-proxy-agent:2.0.5
+----------+------+--------+-----+
| Critical | High | Medium | Low |
+----------+------+--------+-----+
|    26    | 345  |  1447  | 529 |
+----------+------+--------+-----+
Scanning  gcr.io/ml-pipeline/inverse-proxy-agent:2.2.0
+----------+------+--------+-----+
| Critical | High | Medium | Low |
+----------+------+--------+-----+
|    23    | 303  |  1300  | 529 |
+----------+------+--------+-----+
Scanning  gcr.io/ml-pipeline/metadata-envoy:2.0.5
+----------+------+--------+-----+
| Critical | High | Medium | Low |
+----------+------+--------+-----+
|    0     |  1   |   29   |  43 |
+----------+------+--------+-----+
Scanning  gcr.io/ml-pipeline/metadata-envoy:2.2.0
+----------+------+--------+-----+
| Critical | High | Medium | Low |
+----------+------+--------+-----+
|    0     |  0   |   22   |  34 |
+----------+------+--------+-----+
Scanning  gcr.io/ml-pipeline/metadata-writer:2.2.0
+----------+------+--------+-----+
| Critical | High | Medium | Low |
+----------+------+--------+-----+
|    13    | 186  |  968   | 548 |
+----------+------+--------+-----+
Scanning  gcr.io/ml-pipeline/minio:RELEASE.2019-08-14T20-37-41Z-license-compliance
+----------+------+--------+-----+
| Critical | High | Medium | Low |
+----------+------+--------+-----+
|    6     |  17  |   14   |  4  |
+----------+------+--------+-----+
Scanning  gcr.io/ml-pipeline/mysql:8.0.26
+----------+------+--------+-----+
| Critical | High | Medium | Low |
+----------+------+--------+-----+
|    26    | 147  |  145   | 135 |
+----------+------+--------+-----+
Scanning  gcr.io/ml-pipeline/persistenceagent:2.0.5
+----------+------+--------+-----+
| Critical | High | Medium | Low |
+----------+------+--------+-----+
|    1     |  12  |   59   |  6  |
+----------+------+--------+-----+
Scanning  gcr.io/ml-pipeline/persistenceagent:2.2.0
+----------+------+--------+-----+
| Critical | High | Medium | Low |
+----------+------+--------+-----+
|    1     |  7   |   44   |  6  |
+----------+------+--------+-----+
Scanning  gcr.io/ml-pipeline/scheduledworkflow:2.0.5
+----------+------+--------+-----+
| Critical | High | Medium | Low |
+----------+------+--------+-----+
|    1     |  12  |   59   |  6  |
+----------+------+--------+-----+
Scanning  gcr.io/ml-pipeline/scheduledworkflow:2.2.0
+----------+------+--------+-----+
| Critical | High | Medium | Low |
+----------+------+--------+-----+
|    1     |  7   |   44   |  6  |
+----------+------+--------+-----+
Scanning  gcr.io/ml-pipeline/viewer-crd-controller:2.0.5
+----------+------+--------+-----+
| Critical | High | Medium | Low |
+----------+------+--------+-----+
|    1     |  5   |   41   |  2  |
+----------+------+--------+-----+
Scanning  gcr.io/ml-pipeline/viewer-crd-controller:2.2.0
+----------+------+--------+-----+
| Critical | High | Medium | Low |
+----------+------+--------+-----+
|    1     |  1   |   27   |  2  |
+----------+------+--------+-----+
Scanning  gcr.io/ml-pipeline/visualization-server:2.0.5
+----------+------+--------+-----+
| Critical | High | Medium | Low |
+----------+------+--------+-----+
|    8     | 117  |  1529  | 234 |
+----------+------+--------+-----+
Scanning  gcr.io/ml-pipeline/visualization-server:2.2.0
+----------+------+--------+-----+
| Critical | High | Medium | Low |
+----------+------+--------+-----+
|    6     | 113  |  1509  | 232 |
+----------+------+--------+-----+

@hansinikarunarathne
Copy link
Member Author

Even in this excerpt the differences are massive

Scanning  gcr.io/ml-pipeline/api-server:2.0.5
+----------+------+--------+-----+
| Critical | High | Medium | Low |
+----------+------+--------+-----+
|    3     |  36  |   76   |  65 |
+----------+------+--------+-----+
Scanning  gcr.io/ml-pipeline/api-server:2.2.0
+----------+------+--------+-----+
| Critical | High | Medium | Low |
+----------+------+--------+-----+
|    3     |  14  |   62   |  63 |
+----------+------+--------+-----+
Scanning  gcr.io/ml-pipeline/application-crd-controller:20231101
+----------+------+--------+-----+
| Critical | High | Medium | Low |
+----------+------+--------+-----+
|    1     |  13  |   19   |  0  |
+----------+------+--------+-----+
Scanning  gcr.io/ml-pipeline/cache-deployer:2.2.0
+----------+------+--------+-----+
| Critical | High | Medium | Low |
+----------+------+--------+-----+
|    13    |  23  |   77   |  2  |
+----------+------+--------+-----+
Scanning  gcr.io/ml-pipeline/cache-server:2.2.0
+----------+------+--------+-----+
| Critical | High | Medium | Low |
+----------+------+--------+-----+
|    1     |  7   |   44   |  6  |
+----------+------+--------+-----+
Scanning  gcr.io/ml-pipeline/frontend:2.0.5
+----------+------+--------+-----+
| Critical | High | Medium | Low |
+----------+------+--------+-----+
|    4     |  36  |   62   |  10 |
+----------+------+--------+-----+
Scanning  gcr.io/ml-pipeline/frontend:2.2.0
+----------+------+--------+-----+
| Critical | High | Medium | Low |
+----------+------+--------+-----+
|    4     |  35  |   57   |  10 |
+----------+------+--------+-----+
Scanning  gcr.io/ml-pipeline/inverse-proxy-agent:2.0.5
+----------+------+--------+-----+
| Critical | High | Medium | Low |
+----------+------+--------+-----+
|    26    | 345  |  1447  | 529 |
+----------+------+--------+-----+
Scanning  gcr.io/ml-pipeline/inverse-proxy-agent:2.2.0
+----------+------+--------+-----+
| Critical | High | Medium | Low |
+----------+------+--------+-----+
|    23    | 303  |  1300  | 529 |
+----------+------+--------+-----+
Scanning  gcr.io/ml-pipeline/metadata-envoy:2.0.5
+----------+------+--------+-----+
| Critical | High | Medium | Low |
+----------+------+--------+-----+
|    0     |  1   |   29   |  43 |
+----------+------+--------+-----+
Scanning  gcr.io/ml-pipeline/metadata-envoy:2.2.0
+----------+------+--------+-----+
| Critical | High | Medium | Low |
+----------+------+--------+-----+
|    0     |  0   |   22   |  34 |
+----------+------+--------+-----+
Scanning  gcr.io/ml-pipeline/metadata-writer:2.2.0
+----------+------+--------+-----+
| Critical | High | Medium | Low |
+----------+------+--------+-----+
|    13    | 186  |  968   | 548 |
+----------+------+--------+-----+
Scanning  gcr.io/ml-pipeline/minio:RELEASE.2019-08-14T20-37-41Z-license-compliance
+----------+------+--------+-----+
| Critical | High | Medium | Low |
+----------+------+--------+-----+
|    6     |  17  |   14   |  4  |
+----------+------+--------+-----+
Scanning  gcr.io/ml-pipeline/mysql:8.0.26
+----------+------+--------+-----+
| Critical | High | Medium | Low |
+----------+------+--------+-----+
|    26    | 147  |  145   | 135 |
+----------+------+--------+-----+
Scanning  gcr.io/ml-pipeline/persistenceagent:2.0.5
+----------+------+--------+-----+
| Critical | High | Medium | Low |
+----------+------+--------+-----+
|    1     |  12  |   59   |  6  |
+----------+------+--------+-----+
Scanning  gcr.io/ml-pipeline/persistenceagent:2.2.0
+----------+------+--------+-----+
| Critical | High | Medium | Low |
+----------+------+--------+-----+
|    1     |  7   |   44   |  6  |
+----------+------+--------+-----+
Scanning  gcr.io/ml-pipeline/scheduledworkflow:2.0.5
+----------+------+--------+-----+
| Critical | High | Medium | Low |
+----------+------+--------+-----+
|    1     |  12  |   59   |  6  |
+----------+------+--------+-----+
Scanning  gcr.io/ml-pipeline/scheduledworkflow:2.2.0
+----------+------+--------+-----+
| Critical | High | Medium | Low |
+----------+------+--------+-----+
|    1     |  7   |   44   |  6  |
+----------+------+--------+-----+
Scanning  gcr.io/ml-pipeline/viewer-crd-controller:2.0.5
+----------+------+--------+-----+
| Critical | High | Medium | Low |
+----------+------+--------+-----+
|    1     |  5   |   41   |  2  |
+----------+------+--------+-----+
Scanning  gcr.io/ml-pipeline/viewer-crd-controller:2.2.0
+----------+------+--------+-----+
| Critical | High | Medium | Low |
+----------+------+--------+-----+
|    1     |  1   |   27   |  2  |
+----------+------+--------+-----+
Scanning  gcr.io/ml-pipeline/visualization-server:2.0.5
+----------+------+--------+-----+
| Critical | High | Medium | Low |
+----------+------+--------+-----+
|    8     | 117  |  1529  | 234 |
+----------+------+--------+-----+
Scanning  gcr.io/ml-pipeline/visualization-server:2.2.0
+----------+------+--------+-----+
| Critical | High | Medium | Low |
+----------+------+--------+-----+
|    6     | 113  |  1509  | 232 |
+----------+------+--------+-----+

Is there relationship between CVE count and tekton ? can you elaborate on this more ?

@hansinikarunarathne
Copy link
Member Author

See also #2856

@hansinikarunarathne please rebase or create a new PR for this.

I rebased the PR with master

@juliusvonkohout
Copy link
Member

/lgtm

@rimolive is there any plan to revive the tekton repository for 1.10?

@google-oss-prow google-oss-prow bot added the lgtm label Sep 3, 2024
@juliusvonkohout
Copy link
Member

@animeshsingh
@ckadner
@Tomcli
@fenglixa
@pugangxa
@ScrapCodes
@yhwang
@rafalbigaj

Are you still maintaining and planning to update https://github.com/kubeflow/kfp-tekton for KFP 2.2.0+? The last commit is soon 6 months old and it adds a massive amount of CVEs.

@juliusvonkohout
Copy link
Member

Please check the main readme and /hack folder for tekton related things.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Remove the old tekton version
3 participants