My team at Personio have been tracking down CVEs recently and many of them have now been fixed upstream in the latest version of Alpine 3.13.
However we are still seeing vulnerabilities stemming from our usage of the latest version of newrelic/php-daemon
since it appears that this image is still running on an older version of alpine and as a result is missing several important security patches.
I believe all we need todo is bump the version number of your base alpine image in use, I've gone ahead and created a small pull request for this under a new release version following what I see is the convention for this repo:
https://github.com/newrelic/newrelic-php-daemon-docker/pull/37
Hello,
My team at Personio have been tracking down CVEs recently and many of them have now been fixed upstream in the latest version of Alpine 3.13. However we are still seeing vulnerabilities stemming from our usage of the latest version of
newrelic/php-daemon
since it appears that this image is still running on an older version of alpine and as a result is missing several important security patches.I believe all we need todo is bump the version number of your base alpine image in use, I've gone ahead and created a small pull request for this under a new release version following what I see is the convention for this repo: https://github.com/newrelic/newrelic-php-daemon-docker/pull/37
Happy to change/refactor this if needed!
Kind Regards