atomist-playground / maventest

0 stars 0 forks source link

Pin Docker base images in Dockerfile #8

Closed atomist[bot] closed 2 years ago

atomist[bot] commented 3 years ago

This pull request pins the following Docker base images in Dockerfile to their current digests.

https://github.com/atomist-playground/maventest/blob/eab75da28ab2a4e7f27ef237c7a5adcc0b28fe02/Dockerfile#L1-L1

Digest sha256:72922abc95d38e02f750b34800239dc0e2c298e74bfdd970018367f0d9281d5c references a multi-CPU architecture image manifest. This image supports the following architectures:


https://github.com/atomist-playground/maventest/blob/eab75da28ab2a4e7f27ef237c7a5adcc0b28fe02/Dockerfile#L7-L7

Digest sha256:e3168174d367db9928bb70e33b4750457092e61815d577e368f53efb29fea48b references a multi-CPU architecture image manifest. This image supports the following architectures:


Pinning FROM lines to digests makes your builds repeatable. Atomist will raise new pull requests whenever the tag moves, so that you know when the base image has been updated. You can follow a new tag at any time. Just replace the digest with the new tag you want to follow. Atomist, will switch to following this new tag.


File changed:

atomist[bot] commented 3 years ago
Vulnerabilities
Comparison

πŸ‘ No new critical or high vulnerabilities compared with target branch main

πŸ’‘ Rebase branch atomist/pin-docker-base-image/dockerfile to include latest changes from branch main to increase accuracy of vulnerability report


More details are available in the vulnerability report

atomist[bot] commented 2 years ago
Vulnerabilities
Comparison

πŸ‘ No new critical or high vulnerabilities compared with target branch main


More details are available in the vulnerability report

atomist[bot] commented 2 years ago
Vulnerabilities
Comparison

πŸ‘ No new critical or high vulnerabilities compared with target branch main


More details are available in the vulnerability report

atomist[bot] commented 2 years ago
Vulnerabilities
Comparison

🚨 Adds 13 critical and 26 high severity vulnerabilities compared with target branch main

πŸ’‘ Rebase branch atomist/pin-docker-base-image/dockerfile to include latest changes from branch main to increase accuracy of vulnerability report


More details are available in the vulnerability report

atomist[bot] commented 2 years ago
Vulnerabilities
Comparison

πŸ‘ No new critical or high vulnerabilities compared with target branch main

πŸ’‘ Rebase branch atomist/pin-docker-base-image/dockerfile to include latest changes from branch main to increase accuracy of vulnerability report


More details are available in the vulnerability report