Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This a conversation fueled by CVEs mainly.
Scanned the latest released with Trivy:
And here's the overview:
Looking at the history of this project it was once
alpine
: bc4a907Actually wanted to suggest it as a base image since it has decent developer experience compared to distroless, if you don't have to deal with
musl
specifically.What follows is just a test I did on how hard it would be to make it
distroless
.Not very, as it seems - though I don't know about those deps since I didn't need any in my testing.
Here are a few options for this conversation:
alpine
, decent devx, small, almost no CVEsdistroless
, works as far as I can tell but it's a pain to build once you have to deal with depsbookworm
at least since some of the CVEs have already been resolved but are not scheduled to be backported