corretto / corretto-8-docker

Dockerfiles for Amazon Corretto 8
MIT No Attribution
195 stars 40 forks source link

Amazonlinux Base Image has security vulnerabilities #41

Closed albuch closed 5 years ago

albuch commented 5 years ago

Hi, it seems the used base image amazonlinux:2 has publicly known vulnerabilities since at least Sep 19th that have fixes available that are not yet part of the latest image which was published 25days ago. See upstream issue at https://forums.aws.amazon.com/thread.jspa?threadID=310554&tstart=0

Do you monitor corretto images for security issues? Is there something that should be improved in the publishing process?

TianminShi commented 5 years ago

Hi Alex, thank you for rasing your concern. however I think your concern is may already been addressed in here. https://github.com/corretto/corretto-8-docker/issues/26

albuch commented 5 years ago

Hi @TianminShi thanks, I've already created an issue with upstream amazonlinux. See https://github.com/amazonlinux/container-images/issues/30