Skip to content

Conversation

@behnazh-w
Copy link
Member

Summary

This PR updates the base image, upgrades Python to version 3.11.14 for security patches, and enhances the installation process of SLSA Verifier by adding provenance-based binary hash verification.

Description of changes

  • Base Image Update: The base Docker image and related dependencies have been updated to their latest stable versions to ensure continued security and compatibility.
  • Python Upgrade: Python has been upgraded from the previous version to 3.11.14 in response to upstream security patches.
  • SLSA Verifier Installation Improvements: The installation step now extracts the expected SHA-256 hash from the provenance and checks that it matches the hash of the binary.

Signed-off-by: behnazh-w <behnaz.hassanshahi@oracle.com>
@oracle-contributor-agreement oracle-contributor-agreement bot added the OCA Verified All contributors have signed the Oracle Contributor Agreement. label Dec 4, 2025
Signed-off-by: behnazh-w <behnaz.hassanshahi@oracle.com>
@behnazh-w behnazh-w force-pushed the behnazh/update-docker-packages-Dec2025 branch from 657c46b to 4b6fa07 Compare December 4, 2025 02:01
@behnazh-w behnazh-w requested a review from nicallen December 4, 2025 02:08
@behnazh-w behnazh-w merged commit e6aee3e into main Dec 4, 2025
15 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

OCA Verified All contributors have signed the Oracle Contributor Agreement.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants