-
Notifications
You must be signed in to change notification settings - Fork 234
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Bump alpine version to v3.13 (latest) #513
Conversation
hi @Gabitchov , all dockerfiles are generated from scripts, so the place which needs update is here - https://github.com/AdoptOpenJDK/openjdk-docker/blob/master/dockerfile_functions.sh#L156 |
2280082
to
2aa73ae
Compare
@grzesuav Thanks for your feedback. |
2aa73ae
to
d2a0129
Compare
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
lgtm
Hi, |
Hello, What I understood, there is one build by day on change. The one for this PR is on going: https://ci.adoptopenjdk.net/job/openjdk_build_docker_multiarch/231/ I am also pending for an updated image but for the openjdk11 Wait and see... |
@Gabitchov - No joy.. I still see alpine 3.12 in all the docker.xxx files |
Any updates on this. Every version still shows up as using alpine 3.12 . Container Security scanners tools are blocking the older versions due to unresolved CVEs. |
@consult-kk We reverted back to Alpine 3.12 because of #520. Alpine 3.12 is still supported (= receives security fixes), so the claims of the security scanners sounds dubious. |
I will put my trust on an image scanner rather than just claiming it to be "dubious" with out any data backing the claim. |
@consult-kk As you wish, hard data: https://gitlab.alpinelinux.org/alpine/aports/-/merge_requests/11120. https://gitlab.alpinelinux.org/alpine/aports/-/commit/1d0560a9b6b5597b191e5aff69a31c2fe0aba273 shows which releases it's in. |
I bump the version of alpine to the latest stable, 3.13: https://www.alpinelinux.org/releases/