fabric8io-images / java

Java Base Images
Apache License 2.0
176 stars 99 forks source link

base alpine image failing security scan #67

Closed docuedge-wf closed 3 years ago

docuedge-wf commented 3 years ago

the base 3.11 image is showing critical and high vulnerabilities in docker scan. can the base image be pointed to 3.11.12 as per docker scan recommendation

rhuss commented 3 years ago

Good point, unfortunately these images are not maintained very well anymore. From time to time (at most once a year probably) I do an update, so as now (with tag 1.9.0).

I would recommend to switch to a better maintained and supported image in the future.

rhuss commented 3 years ago

oops, just found out that Docker hub does not support free automated builds anymore (probably already since some time 😬 ).

I'm going to push the images with a 1.9.0 tag from my machine now, but that will be probably the last time I will do that. Need some automation for that (but have no time really)