Skip to content

FIx CVE's from Maven, check mvn usage in enablement #13

@eformat

Description

@eformat

Fix CVE's brought in by maven install in Dockerfile. We could use rh-maven package if appropriate

ARG MAVEN_VERSION=3.6.1
ARG MAVEN_URL=https://archive.apache.org/dist/maven/maven-3/$MAVEN_VERSION/binaries/apache-maven-$MAVEN_VERSION-bin.tar.gz

CVE's reposted in quay.io here:

https://quay.io/repository/rht-labs/stacks-node-rhel7-ansible

Also, we could question the need for maven ... ultimately we need java in the image for testing (selenium dependency) but mvn is nice to have ?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions