Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

pins alpine version to latest 3.18.x #123

Merged
merged 1 commit into from
Sep 15, 2023

Conversation

rubyalwaystaken
Copy link
Contributor

Currently the latest docker image of helm-exporter is built with alpine 3.18.2 which has multiple critical security vulnerabilities (busybox, ssl_client). Pinning the alpine version to the latest 3.18 release fixes those vulnerabilities

@BlacCello
Copy link

BlacCello commented Sep 15, 2023

I suggest to add Depdendabot also for Dockerfiles to this repository, so that the pinned alpine base image will be updated automatically in the future.

@sstarcher sstarcher merged commit 5dba6e8 into sstarcher:master Sep 15, 2023
3 checks passed
@BlacCello
Copy link

BlacCello commented Sep 28, 2023

Hey @sstarcher ,
Thanks for merging this. Would it be okay for you to create a new patch release that includes this fix, so that the upstream docker image won't have CVE-2022-48174 detected anymore?

@sstarcher
Copy link
Owner

1.2.11 created assuming pipelines work

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants