CircleCI-Public / cimg-base

The CircleCI Base (Ubuntu) Docker Convenience Image.
https://circleci.com/developer/images/image/cimg/base
MIT License
74 stars 42 forks source link

Update docker-compose to latest version to fix CVE-2024-21626 #265

Closed afterdesign closed 6 months ago

afterdesign commented 6 months ago

For our official CircleCI Docker Convenience Image support policy, please see CircleCI docs.

This policy outlines the release, update, and deprecation policy for CircleCI Docker Convenience Images.


Description

Update docker-compose to latest version to fix CVE-2024-21626

Reasons

Docker compose depends on containerd go module which is part of CVE-2024-21626. To fix this docker-compose needs to be at least in version 1.26.0

Checklist

Please check through the following before opening your PR. Thank you!

bjohnso5 commented 6 months ago

tracked in #266

bjohnso5 commented 6 months ago

Thank you for the contribution!