Skip to content

Commit 9bd2c20

Browse files
committed
fix: use --releasever latest for dnf security upgrades
The NVIDIA CUDA base image pins to an older AL2023 release version, so dnf upgrade --security misses patches available in newer releases. Adding --releasever latest ensures all available security fixes are applied, including fixes for sqlite, libxml2, libtasn1, glib2, libcap, openssl, and glibc CVEs. Signed-off-by: Junpu Fan <junpu@amazon.com>
1 parent 14b1210 commit 9bd2c20

File tree

1 file changed

+3
-3
lines changed

1 file changed

+3
-3
lines changed

docker/lambda/Dockerfile

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -101,7 +101,7 @@ RUN --mount=type=cache,target=/root/.cache/uv \
101101
FROM nvidia/cuda:12.8.1-runtime-amzn2023 as base-py3
102102
LABEL maintainer="Amazon AI"
103103
LABEL dlc_major_version="1"
104-
RUN dnf upgrade -y --security && dnf clean all && rm -rf /var/cache/dnf
104+
RUN dnf upgrade -y --security --releasever latest && dnf clean all && rm -rf /var/cache/dnf
105105
COPY --from=builder-base-py3 /var/lang /var/lang
106106
COPY --from=lambda-python /var/runtime /var/runtime
107107
COPY --from=rie-downloader /usr/local/bin/aws-lambda-rie /usr/local/bin/aws-lambda-rie
@@ -145,7 +145,7 @@ CMD ["handler.handler"]
145145
FROM nvidia/cuda:12.8.1-runtime-amzn2023 as cupy-py3
146146
LABEL maintainer="Amazon AI"
147147
LABEL dlc_major_version="1"
148-
RUN dnf upgrade -y --security && dnf clean all && rm -rf /var/cache/dnf
148+
RUN dnf upgrade -y --security --releasever latest && dnf clean all && rm -rf /var/cache/dnf
149149
COPY --from=builder-cupy-py3 /var/lang /var/lang
150150
COPY --from=lambda-python /var/runtime /var/runtime
151151
COPY --from=rie-downloader /usr/local/bin/aws-lambda-rie /usr/local/bin/aws-lambda-rie
@@ -188,7 +188,7 @@ CMD ["handler.handler"]
188188
FROM nvidia/cuda:12.8.1-runtime-amzn2023 as pytorch-py3
189189
LABEL maintainer="Amazon AI"
190190
LABEL dlc_major_version="1"
191-
RUN dnf upgrade -y --security \
191+
RUN dnf upgrade -y --security --releasever latest \
192192
&& dnf install -y --setopt=install_weak_deps=False \
193193
libxcb libX11 libXext libXfixes alsa-lib \
194194
&& dnf clean all && rm -rf /var/cache/dnf

0 commit comments

Comments
 (0)