Skip to content

Commit 115c155

Browse files
committed
remover image vulns
Signed-off-by: ashnamehrotra <ashnamehrotra@gmail.com>
1 parent 3bf4801 commit 115c155

File tree

1 file changed

+5
-5
lines changed

1 file changed

+5
-5
lines changed

Dockerfile

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ ARG BUILDKIT_SBOM_SCAN_STAGE=builder,manager-build,collector-build,remover-build
77
FROM --platform=$TARGETPLATFORM $TRIVY_BINARY_IMG AS trivy-binary
88

99
# Build the manager binary
10-
FROM --platform=$BUILDPLATFORM golang:1.23.4-bookworm AS builder
10+
FROM --platform=$BUILDPLATFORM golang:1.25.3-bookworm AS builder
1111
WORKDIR /workspace
1212
# Copy the Go Modules manifests
1313
COPY go.mod go.mod
@@ -56,19 +56,19 @@ COPY --from=manager-build /workspace/out/manager .
5656
USER 65532:65532
5757
ENTRYPOINT ["/manager"]
5858

59-
FROM --platform=$TARGETPLATFORM gcr.io/distroless/static:latest as collector
59+
FROM --platform=$TARGETPLATFORM gcr.io/distroless/static-debian12:nonroot AS collector
6060
COPY --from=collector-build /workspace/out/collector /
6161
ENTRYPOINT ["/collector"]
6262

63-
FROM --platform=$TARGETPLATFORM gcr.io/distroless/static:latest as remover
63+
FROM --platform=$TARGETPLATFORM gcr.io/distroless/static-debian12:nonroot AS remover
6464
COPY --from=remover-build /workspace/out/remover /
6565
ENTRYPOINT ["/remover"]
6666

67-
FROM --platform=$TARGETPLATFORM gcr.io/distroless/static:latest as trivy-scanner
67+
FROM --platform=$TARGETPLATFORM gcr.io/distroless/static-debian12:nonroot AS trivy-scanner
6868
COPY --from=trivy-scanner-build /workspace/out/trivy-scanner /
6969
COPY --from=trivy-binary /usr/local/bin/trivy /
7070
WORKDIR /var/lib/trivy
7171
ENTRYPOINT ["/trivy-scanner"]
7272

73-
FROM gcr.io/distroless/static:nonroot as non-vulnerable
73+
FROM gcr.io/distroless/static:nonroot AS non-vulnerable
7474
COPY --from=builder /tmp /tmp

0 commit comments

Comments
 (0)