Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

OpenSSL 3 - Amazon Linux base #123

Closed
JohnPreston opened this issue Nov 2, 2022 · 2 comments
Closed

OpenSSL 3 - Amazon Linux base #123

JohnPreston opened this issue Nov 2, 2022 · 2 comments
Labels
bug Something isn't working

Comments

@JohnPreston
Copy link

JohnPreston commented Nov 2, 2022

Hi there.
I did follow the Security report guidelines, but for the sake of community observability, although corretto is not mentionned in the https://aws.amazon.com/security/security-bulletins/AWS-2022-008/ bulletin, given base images are using Amazon Linux, which is on it, might be worth to clarify / publish images with all the latest security patches.

Thank you,

PS: The AmazonLinux team did publish 17h a patched version: https://gallery.ecr.aws/amazonlinux/amazonlinux
So worth aligning to that 🙏

@JohnPreston JohnPreston added the bug Something isn't working label Nov 2, 2022
@davecurrie
Copy link

Hi. Corretto Docker images are based on Amazon Linux 2, which is not affected per the security bulletin you linked to. Corretto is covered by the sentence in the advisory: "AWS services are not affected, and no customer action is required."

The new images published by Amazon Linux are for the AL 2022 preview, which we don't use as a base image.

@JohnPreston
Copy link
Author

Sorry for the confusion on my end, that makes sense, thanks for the prompt reply!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
None yet
Development

No branches or pull requests

2 participants