docker-library / cassandra

Docker Official Image packaging for Cassandra
Apache License 2.0
262 stars 281 forks source link

Fix CVEs by updating deps #202

Closed laballab closed 4 years ago

laballab commented 4 years ago

Hi, Below CVEs are present in this image due to sqlite3 v.3.22.0-1ubuntu0.2:

This is patched in v.3.22.0-1ubuntu0.3, possible to update to this and fix it? Thanks all.

laballab commented 4 years ago

I should mention, this issue is present in cassandra:3.11.6 currently

yosifkit commented 4 years ago

We strive to publish updated images at least monthly for Debian and Ubuntu. We also rebuild earlier if there is a critical security need

- https://github.com/docker-library/faq#why-does-my-security-scanner-show-that-an-image-has-cves

This means that all official-images FROM those (and their descendants) also get rebuilt. The last ubuntu update was https://github.com/docker-library/official-images/pull/7510, so about 21 days ago. It looks like most of these involve chrome's usage of sqlite and so aren't really applicable to cassandra, right? I don't see anything that warrants causing an early rebuild of all ubuntu based images, so we'll wait for the regular rebuild in about a week.

tianon commented 4 years ago

It looks like these are all fixed :+1: