temporalio / docker-builds

Temporal service Docker images build
https://hub.docker.com/r/temporaliotest/auto-setup
MIT License
30 stars 59 forks source link

[Bug] Alpine 3.18 includes openssl vulnerabilities #180

Closed GerardVivancos closed 10 months ago

GerardVivancos commented 10 months ago

What are you really trying to do?

Our organization deploys Temporal and our internal security scans detected vulnerabilities in temporalio/ui:2.22.0 and earlier.

The origin of them is alpine:3.18. We want to be able to deploy Temporal without these vulnerabilities.

Describe the bug

CVE-2023-5363 detected by Trivy

Minimal Reproduction

trivy image --severity HIGH,CRITICAL temporalio/ui:2.22.0