Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR adds the kernel-tools package to the version-locked packages in the AL2 AMI. Currently, kernel-tools can be updated to versions independent of the installed kernel version when applying other updates when we run
yum update -y
to patch the OS. This gets flagged as a "high" vulnerability by our Tenable scans, because Tenable thinks that there is a pending kernel upgrade that we need to reboot our EC2s for to apply, even though there is no pending kernel upgrade:By version locking kernel tools to the kernel version, this should no longer be an issue, and we can coordinate kernel-tools upgrades with kernel upgrades by manually unlocking the packages when we are ready to apply updates.
By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the terms of your choice.
Testing Done
See this guide for recommended testing for PRs. Some tests may not apply. Completing tests and providing additional validation steps are not required, but it is recommended and may reduce review time and time to merge.