Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CNB has no new version published. We need example of Rebase. #169

Closed
msathe-tech opened this issue Jan 13, 2022 · 4 comments
Closed

CNB has no new version published. We need example of Rebase. #169

msathe-tech opened this issue Jan 13, 2022 · 4 comments
Labels
kind/documentation Improvements or additions to documentation

Comments

@msathe-tech
Copy link

gcr.io/buildpacks/builder:v1 for Java apps has 36 CVEs.
There is no new version published.
We also need a new version to check out the Rebase functionality.

@matthewrobertson
Copy link
Member

We release updates to the base images very frequently. Could you please share the details of which CVEs you are finding in the images and how you are scanning? AR auto scanning turns up a few low severity CVEs but none of them have patches available so an update won't help.

@matthewrobertson
Copy link
Member

I agree we need better documentation on how to rebase to update the base image layers.

We should also provide docs on how to remove unnecessary packages from the base image. This would allow users to eliminate CVEs that were introduced by packages that are not required by their application.

@matthewrobertson matthewrobertson added the kind/documentation Improvements or additions to documentation label Jan 28, 2022
@jama22
Copy link
Collaborator

jama22 commented Feb 9, 2023

We just published an updated builder using Ubuntu 22 as the base image. This builder has substantially fewer CVEs, see #271

I think the remaining work here might be to demonstrate how to execute a rebase.

@jama22
Copy link
Collaborator

jama22 commented May 5, 2023

@msathe-tech you can check out my demo of how to use rebase in my post here #300

Feedback welcome!

@jama22 jama22 closed this as completed May 5, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
kind/documentation Improvements or additions to documentation
Projects
None yet
Development

No branches or pull requests

3 participants