Skip to content

Update packages in alpine image #161

@digitalghost-dev

Description

@digitalghost-dev

In the main Dockerfile using alpine3.22, there are two packages that have had their vulnerabilities fixed:

NAME             INSTALLED   FIXED IN  TYPE       VULNERABILITY        SEVERITY  EPSS %  RISK
libcrypto3       3.5.0-r0    3.5.1-r0  apk        CVE-2025-4575        Medium    6.43    < 0.1
libssl3          3.5.0-r0    3.5.1-r0  apk        CVE-2025-4575        Medium    6.43    < 0.1

Adding a RUN apk upgrade && \ to the build stage of the Dockerfile updates these since the alpine image hasn't been updated yet.

Metadata

Metadata

Assignees

No one assigned

    Labels

    securityIssues related to security.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions