Update docker.io/redis Docker tag to v8.10.2

Share
Update docker.io/redis Docker tag to v8.10.2
Photo by Silas Köhler / Unsplash

Successfully upgraded the Docker container on the Database Host by means of Watchtower container with dependency update facilitated by Mend's Renovate Bot and on the Mastodon instance manually with Docker compose.

This MR contains the following updates:

Package Update Change
docker.io/redis (source) patch 8.10.1-alpine → 8.10.2-alpine

Release Notes

redis/redis (docker.io/redis)

v8.10.2

Compare Source

Update urgency: SECURITY: There are security fixes in the release.

Security fixes
  • #​15673 Commands queued in a transaction could still access keys whose ACL permissions were revoked before the transaction was executed
  • #​15722 The cluster bus protocol has no authentication of its own unless tls-cluster is enabled, so any host able to reach a node's bus port could join the cluster and threaten it. A cluster node now warns at startup when its bus port is left unauthenticated, and the new cluster-bus-port-protected-mode option (default no) makes refusing to run in that state an explicit choice: set it to yes and the node starts only when tls-cluster authenticates the bus
  • TimeSeries: Prevented Redis from crashing when adding samples to a compressed Time Series key restored from a malformed RDB payload
  • RedisSearch: KNN queries on indexes with very long vector field names could cause the server to crash
  • Vector Sets: Deeply nested JSON used in Vector Set queries could cause the server to crash

Read more

Me on Mastodon - This link is here for verification purposes.