phusion / baseimage-docker

A minimal Ubuntu base image modified for Docker-friendliness
http://phusion.github.io/baseimage-docker/
MIT License
8.96k stars 1.09k forks source link

Security vulnerabilities #622

Closed gr8bit closed 1 year ago

gr8bit commented 1 year ago

(Inspired by https://github.com/phusion/passenger-docker/issues/350)

There currently are a few security vulnerabilities in the image, one of which even is of severity HIGH: Bildschirm­foto 2023-01-07 um 21 55 04

Would it be possible to update the packages in the image to get rid of those vulnerabilities?

github-actions[bot] commented 1 year ago

This Issue has been automatically marked as "stale" because it has not had recent activity (for 15 days). It will be closed if no further activity occurs. Thanks for the feedback.

samip5 commented 1 year ago

@gr8bit Which baseimage version was used? phusion/baseimage:master is 11 months old and there are newer ones.

oozone commented 1 year ago

Where can we find the newer images, it's not clear, thanks.

gr8bit commented 1 year ago

phusion/passenger-docker uses phusion/baseimage-docker:master and the Passenger-image version I was commenting on here was built on Dec 20th. So it probably used that 11 month old one...

samip5 commented 1 year ago

Where can we find the newer images, it's not clear, thanks.

We have been making releases when a new image is available (it gets built on release): https://github.com/phusion/baseimage-docker/releases

Latest is currently jammy-1.0.1.

samip5 commented 1 year ago

Closing as invalid.