Skip to content

Commit de1e010

Browse files
authored
Pin all base images in Dockerfiles to SHA256 digests for supply chain security (Scorecard remediation) (#1188)
1 parent 32cff72 commit de1e010

File tree

5 files changed

+5
-5
lines changed

5 files changed

+5
-5
lines changed

scripts/packages/packager/Dockerfile

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
ARG package_type
22

3-
FROM docker.io/golang:1.24-bullseye AS base
3+
FROM docker.io/golang@sha256:62ba6b19de03e891f7fa1001326bd48411f2626ff35e7ba5b9d890711ce581d9 AS base
44

55
ARG PKG_VER="1.17.5"
66
ARG PKG_DIR="/tmp/pkg"

test/docker/load/Dockerfile

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
FROM ubuntu:24.04 as base
1+
FROM ubuntu@sha256:a08e551cb33850e4740772b38217fc1796a66da2506d312abe51acda354ff061 AS base
22
LABEL maintainer="NGINX Docker Maintainers <[email protected]>"
33

44
# https://askubuntu.com/questions/909277/avoiding-user-interaction-with-tzdata-when-installing-certbot-in-a-docker-contai

test/integration/auxiliarycommandserver/Dockerfile

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
FROM debian:buster-slim
1+
FROM debian:buster-slim@sha256:bb3dc79fddbca7e8903248ab916bb775c96ec61014b3d02b4f06043b604726dc
22

33
WORKDIR /mock-management-plane-grpc
44
COPY ./build/mock-management-plane-grpc ./

test/mock/collector/mock-collector/Dockerfile

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
FROM golang:bookworm
1+
FROM golang:bookworm@sha256:ef8c5c733079ac219c77edab604c425d748c740d8699530ea6aced9de79aea40
22

33
WORKDIR /mock-management-otel-collector
44
COPY ./build/mock-management-otel-collector ./

test/mock/grpc/Dockerfile

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
FROM debian:buster-slim
1+
FROM debian:buster-slim@sha256:bb3dc79fddbca7e8903248ab916bb775c96ec61014b3d02b4f06043b604726dc
22

33
WORKDIR /mock-management-plane-grpc
44
COPY ./build/mock-management-plane-grpc ./

0 commit comments

Comments
 (0)