docker-library / httpd

Docker Official Image packaging for Apache HTTP Server
https://httpd.apache.org
Apache License 2.0
309 stars 347 forks source link

Update lua-dev (5.1) to lua5.4-dev to remove Lua vulnerabilities #260

Closed Maroko closed 4 months ago

yosifkit commented 4 months ago

What perceived vulnerability is being fixed by this bump? Alpine often backports security fixes, so I highly doubt there is an active CVE (try https://security.alpinelinux.org/vuln/CVE-2024-0727 but replaced with the CVE number that you have).


I'm not sure we can just bump this without introduction breaking changes for many users since every Lua bump has incompatibilities with the previous version:

Maroko commented 4 months ago

Looks like a mistake on my side. My security scanner (Blackduck) mapped multiple CVEs (including CVE-2022-28805) to Lua Version 5.1.5.

Thanks for your time, I'm closing this PR.