Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Provide regular updates of Docker images (was: CVE's CBL-Mariner) #24

Closed
ingmars1709 opened this issue Mar 15, 2022 · 8 comments
Closed
Assignees
Labels
bug Something isn't working
Milestone

Comments

@ingmars1709
Copy link

Hi,

According to https://github.com/microsoft/CBL-Mariner/releases/tag/1.0.20220307-1.0
there are quite some CVE's fixed.

Are these incorporated into the mcr.microsoft.com/openjdk/jdk:11-mariner image as well?

@gdams
Copy link
Member

gdams commented Mar 16, 2022

This is a good question. We don't currently rebuild the base images until a new OpenJDK release is available. We likely need to listen to changes in the base images and rebuild when they do.

@karianna
Copy link
Member

karianna commented Mar 16, 2022

@milderhc can we listen in on security pointy releases of Linux distributions? Intriguing thought.

@karianna karianna added the bug Something isn't working label Mar 16, 2022
@ingmars1709
Copy link
Author

Is this something we can expect to be solved in the near future?
We are relying heavily on this image and it generates a lot of High Findings in Azure Security portal.

@karianna
Copy link
Member

karianna commented Apr 12, 2022

Is this something we can expect to be solved in the near future? We are relying heavily on this image and it generates a lot of High Findings in Azure Security portal.

Thanks for your patience! We're discussing this internally so we can put out a public policy and will respond back here in the next week or so.

@d3r3kk
Copy link
Contributor

d3r3kk commented Apr 13, 2022

We can certainly create a scheduled trigger in our GH/AzDO that would simply inspect the CBL-Mariner releases and take action if a release we've not seen before shows up. I'll see if I can rig something up in the next few days.

@d3r3kk d3r3kk closed this as completed Apr 13, 2022
@brunoborges
Copy link
Member

@d3r3kk mind if we keep this issue open until this is addressed?

@karianna karianna reopened this Apr 17, 2022
@brunoborges brunoborges changed the title CVE's CBL-Mariner Provide regular updates of Docker images (was: CVE's CBL-Mariner) Apr 18, 2022
@brunoborges brunoborges added this to the July PSU 2022 milestone May 12, 2022
@brunoborges
Copy link
Member

We will update weekly, starting on or before the July PSU 2022.

@joe-braley
Copy link
Contributor

@brunoborges @karianna

I believe this can be closed. Automated process checks twice per day for changes in the base image digest. Once a detected changes occurs the image build pipeline is executed, and changes pushed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
None yet
Development

No branches or pull requests

7 participants