Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Remove archive php.tar.xz from final images #1487

Closed
vladislavzl opened this issue Jan 19, 2024 · 1 comment
Closed

Remove archive php.tar.xz from final images #1487

vladislavzl opened this issue Jan 19, 2024 · 1 comment

Comments

@vladislavzl
Copy link

The php.tar.xz archive contains tests that are detected as malware.
Like this:
layer.tar//usr/src/php.tar.xz//xz//php-8.1.22/ext/phar/tests/bug81726.gz - a hacktool program Tool.Zipbomb.3
I believe that the archive isn't needed in final php images.

@yosifkit
Copy link
Member

Duplicate of #488. The PHP source is kept so that users can install extensions that are not included by default (like via the docker-php-ext-* scripts).

Related issue: #1394

@tianon tianon closed this as completed Jan 19, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants