atomist-skills / skill-base

Apache License 2.0
0 stars 0 forks source link

Pin 2 APT packages #40

Closed atomist[bot] closed 3 years ago

atomist[bot] commented 3 years ago

This pull request pins 2 APT packages in Dockerfile to the latest available version.

Atomist uses the APT package sources configured in the base image to determine latest available versions. Use a comment like # atomist:apt-source=deb https://deb.nodesource.com/node_14.x hirsute main to add additional APT sources. Disable pinning of packages by placing # atomist:apt-ignore as comment before a RUN instruction.


File changed:


atomist/docker-base-image-policy · Configure

atomist[bot] commented 3 years ago

badge

Path: Dockerfile · Docker image scan

Vulnerability report for image atomist/skill at digest sha256:f322f4005c1c2e8e399b4e99300b43fdf1cbc5beb83e702bd8826e925f4c8fb9.

Detected 2 critical, 23 high, 30 medium and 1 low severity vulnerabilities.


More details are available in the vulnerability report.