eclipse-tractusx / sldt-semantic-hub

Apache License 2.0
6 stars 10 forks source link

TRG 4.02 Using un-altered container base image #191

Closed SebastianBezold closed 9 months ago

SebastianBezold commented 9 months ago

The Dockerfile present for tag v0.2.14 (the release version) does use the alpine package manager to upgrade system dependencies. These kind of upgrades alter the base container image in a way, that we cannot rely on the published container scans provided by DockerHub. Therefore package manager updates/upgrades must not be present in our Dockerfiles

See the upgraded TRG 4.02 descriptions for a more detailed explanation

shijinrajbosch commented 9 months ago

Hi @SebastianBezold,

Thanks for the review comment. We will check the issue.