docker-library / php

Docker Official Image packaging for PHP
https://php.net
MIT License
3.77k stars 2k forks source link

Update apache 2.4.57-2 to 2.4.58-1 #1499

Closed jeritiana closed 3 months ago

jeritiana commented 4 months ago

Is there a timeline to update the used apache version from 2.4.57-2 to 2.4.58-1? The latest version fixes identified CVEs. Thanks

tianon commented 4 months ago

These are not (and are not likely to be; see <no-dsa> tags in the Debian Security Team notes) fixed in any stable release of Debian:

tianon commented 4 months ago

(See also https://github.com/docker-library/faq#why-does-my-security-scanner-show-that-an-image-has-cves)

duprasf commented 3 months ago

I'm maintaining a site that needs to be PCI-DSS compliant and we need Apache 2.4.58 to be compliant. So an upgrade would be appreciated.

tianon commented 3 months ago

All available security updates from Debian are applied in our images (as noted and linked above), and I'm afraid there is not anything more we're going to do here.