Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

eclipse-temurin:17-jre-alpine vulnerabilities #576

Closed
zopahima opened this issue Jun 10, 2024 · 5 comments
Closed

eclipse-temurin:17-jre-alpine vulnerabilities #576

zopahima opened this issue Jun 10, 2024 · 5 comments

Comments

@zopahima
Copy link

eclipse-temurin:17-jre-alpine image contains multiple old vulnerabilities, is there any plan to address them in the near future? when can expected to get a patched version?
vul scan taken by trivy scanner.

image

@karianna
Copy link
Contributor

karianna commented Jun 10, 2024

The base layer gets updated by DockerHub (so you'll need to report to them), you can also tdnf update in the mean time.

@zopahima
Copy link
Author

zopahima commented Jun 10, 2024

@karianna Already did it, I was referred to adoptium.
See - docker/roadmap#675

@omni-htg
Copy link

omni-htg commented Jun 11, 2024

@zopahima As you can see in DockerHub, the last alpine:3.19 was built 5 months ago, and the image eclipse-temurin:17-jre-alpine you're pointing to was built after that using the latest 17.0.11+9 version.
So unless there's an update to alpine 3.19 or a new openjdk version, the image is not getting updated.
Perhaps the folks at Alpine could see this and trigger a bump on 3.19, give them a try.

EDIT: Apologies, it seems that alpine:3.20 has already been merged into temurin so it's only a matter of time until it gets to DockerHub.

@karianna
Copy link
Contributor

@karianna Already did it, I was referred to adoptium. See - docker/roadmap#675

I think that's a different place to DockerHub - but I appreciate that this is frustrating, we need a better round robin policy here.

@zopahima
Copy link
Author

@omni-htg Thanks!! Where can I track alpine merges into temurin? How can I track when it gets into DockerHub?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants