You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
I have already (please mark the applicable with an x):
Confirmed this is the right place to raise the issue - only issues related to the Dockerization of the Pact Broker should be raised here. Issues related to the Pact Broker application itself should be raised in the Pact Broker project.
Upgraded to the latest Pact Broker Docker image OR
Checked the CHANGELOG to see if the issue I am about to raise has been fixed
When scanning the 2.114.0-pactbroker2.108.0 image using Jfrog Xray we find that it has an open critical CVE-2022-48174 security issue. The problem is in busybox:1.35.0-r29 which is included in Alpine 3.17.
Alpine 3.17 also contains a few other packages with open CVE:s of lower severity.
Upgrading to use ruby:3.2.3-alpine3.19 as base image remedies these issues.
Steps to reproduce
N/A
Relevent log files
N/A
The text was updated successfully, but these errors were encountered:
jorander
added a commit
to jorander/pact-broker-docker
that referenced
this issue
Jan 29, 2024
Pre issue-raising checklist
I have already (please mark the applicable with an
x
):Software versions
Expected behaviour
No critical CVE:s found when scanning the image.
Actual behaviour
When scanning the 2.114.0-pactbroker2.108.0 image using Jfrog Xray we find that it has an open critical CVE-2022-48174 security issue. The problem is in busybox:1.35.0-r29 which is included in Alpine 3.17.
Alpine 3.17 also contains a few other packages with open CVE:s of lower severity.
Upgrading to use ruby:3.2.3-alpine3.19 as base image remedies these issues.
Steps to reproduce
N/A
Relevent log files
N/A
The text was updated successfully, but these errors were encountered: