Skip to content

Conversation

@vtaskow
Copy link
Contributor

@vtaskow vtaskow commented Dec 1, 2025

Why

Motivation

When Snyk scans ubi10 images, it throws false positive CVEs for libraries that are already upgraded. It seems that their ubi10 scans are not up-to-date yet since ubi10 is still a relatively new image tag. Scans for 9.7 pass and there are no High / Critical CVEs there.

What

Summary of changes

  • Changed the base conda image to use 9.7
  • Changed the alibi component images to use the conda9 with ubi9.7 tag image
  • Changed the python wrapper image to use conda9
  • Changed the tensorflow serving image to use conda9

Checklist

  • Added/updated unit tests
  • Added/updated documentation
  • Checked for typos in variable names, comments, etc.
  • Added licences for new files

Testing

  • Rebuilt all the images in the changed files

@vtaskow vtaskow requested a review from tyndria December 1, 2025 18:02
@vtaskow vtaskow changed the title chore(): Downgrade to ubi9.7 for Snyk to pass chore(images): Downgrade to ubi9.7 for Snyk to pass Dec 1, 2025
@vtaskow vtaskow merged commit 9ce1f93 into release-1.19.0-prep Dec 1, 2025
@vtaskow vtaskow deleted the downgrade-redhat-ubi-to-9.7-due-to-snyk-failing-for-10 branch December 1, 2025 18:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants