Skip to content

Update Alpine image to version 3.16#1

Merged
nunoapfernandes merged 1 commit intomasterfrom
nf/update_alpine_version
Jun 15, 2022
Merged

Update Alpine image to version 3.16#1
nunoapfernandes merged 1 commit intomasterfrom
nf/update_alpine_version

Conversation

@nunoapfernandes
Copy link

Why:

We're using this action for a while (3 years) and it is still being built based on a outdated alpine version. A docker scan showed that it has a critical vulnerability that it's fixed on later versions.
Screenshot 2022-06-15 at 18 05 51
More info: https://security.snyk.io/vuln/SNYK-ALPINE310-APKTOOLS-1534688

Doing the same scan when using alpine:3.16 showed no known vulnerabilities.
Screenshot 2022-06-15 at 18 07 46

Also, since the action has no changes for a while, it's best if we keep doing security updates while we still use it.

This addresses the issue by:

  • Update docker container alpine:3.10 to alpine:3.16 (latest ATOW)

@nunoapfernandes nunoapfernandes merged commit d6a7ae9 into master Jun 15, 2022
@nunoapfernandes nunoapfernandes deleted the nf/update_alpine_version branch June 15, 2022 17:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant