Skip to content
This repository has been archived by the owner on Jun 6, 2023. It is now read-only.

update the alpine base image from 3.14.0 to 3.14.1 #60

Closed
xquery opened this issue Aug 30, 2021 · 2 comments
Closed

update the alpine base image from 3.14.0 to 3.14.1 #60

xquery opened this issue Aug 30, 2021 · 2 comments

Comments

@xquery
Copy link
Member

xquery commented Aug 30, 2021

trivy image curlimages/curl
2021-08-30T15:34:48.134+0200 WARN You should avoid using the :latest tag as it is cached. You need to specify '--clear-cache' option when :latest image is changed
2021-08-30T15:34:48.139+0200 INFO Need to update DB
2021-08-30T15:34:48.139+0200 INFO Downloading DB...
23.09 MiB / 23.09 MiB [--------------------------------------------------------------------------------------------------------------------------] 100.00% 1.14 MiB p/s 21s
2021-08-30T15:35:15.867+0200 WARN This OS version is not on the EOL list: alpine 3.14
2021-08-30T15:35:15.867+0200 INFO Detecting Alpine vulnerabilities...
2021-08-30T15:35:15.867+0200 INFO Trivy skips scanning programming language libraries because no supported file was detected
2021-08-30T15:35:15.867+0200 WARN This OS version is no longer supported by the distribution: alpine 3.14.0
2021-08-30T15:35:15.868+0200 WARN The vulnerability detection may be insufficient because security updates are not provided

curlimages/curl (alpine 3.14.0)

Total: 5 (UNKNOWN: 0, LOW: 0, MEDIUM: 2, HIGH: 2, CRITICAL: 1)

+--------------+------------------+----------+-------------------+---------------+---------------------------------------+
| LIBRARY | VULNERABILITY ID | SEVERITY | INSTALLED VERSION | FIXED VERSION | TITLE |
+--------------+------------------+----------+-------------------+---------------+---------------------------------------+
| apk-tools | CVE-2021-36159 | CRITICAL | 2.12.5-r1 | 2.12.6-r0 | libfetch before 2021-07-26, as |
| | | | | | used in apk-tools, xbps, and |
| | | | | | other products, mishandles... |
| | | | | | -->avd.aquasec.com/nvd/cve-2021-36159 |
+--------------+------------------+----------+-------------------+---------------+---------------------------------------+

@eXeDK
Copy link

eXeDK commented Sep 2, 2021

Please update to alpine 3.14.2 instead: https://alpinelinux.org/posts/Alpine-3.14.2-released.html

@xquery
Copy link
Member Author

xquery commented Sep 22, 2021

latest release uses alpine 3.14.2

@xquery xquery closed this as completed Sep 22, 2021
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Development

No branches or pull requests

2 participants