-
Notifications
You must be signed in to change notification settings - Fork 11
CVE on full builder image #625
Comments
@paketo-buildpacks/stacks-contributors @paketo-buildpacks/stacks-maintainers (or maybe @paketo-buildpacks/builders-contributors @paketo-buildpacks/builders-maintainers) the linked CVE information (https://ubuntu.com/security/CVE-2022-1015) shows that there is currently no upstream fix yet for Am I correct in my understanding that this will be automatically fixed by our automation when there is an upstream fix? |
Yes, if an Ubuntu Security Notice (USN) is published for Bionic. I don’t see a USN published for bionic for this CVE https://ubuntu.com/security/notices?order=newest&release=bionic&details=CVE-2022-1015. Once a USN is released for 18.04 it should be picked up by https://github.com/paketo-buildpacks/stack-usns/actions/workflows/get-usns.yml which will be picked up by the stacks and auto-released if there are any relevant packages to be updated. |
https://github.com/orgs/paketo-buildpacks/teams/builders-contributors https://github.com/orgs/paketo-buildpacks/teams/builders-maintainers) Have a query. why is that our builpacks not using unbuntu 20.04 version ? is there a specific reason |
We did not prioritize creating 20.04 stacks. However, we are currently working on creating builders that support Ubuntu 2022.04 - Jammy Jellyfish. See this issue: paketo-buildpacks/stacks#133
You can pin to a specific builder version by pulling a specific builder version tag. For example, |
We have Jammy stacks today. What else remains to close this issue out? |
Looks good to me. @aadi555, anything further you'd like to see? |
Thanks will close the issue. However lot of unwanted packages in full builder leading to security issues. Like Ruby package. Hope this will be addressed soon. Closing the issue. Thanks @fg-j @ryanmoran |
[## What happened?
CVE Issues found with full builder when building application images
CVE-2022-1015
https://ubuntu.com/security/CVE-2022-1015
Build Configuration
What platform (
pack
,kpack
,tekton
buildpacks plugin, etc.) are youusing? Please include a version.
What buildpacks are you using? Please include versions.
What builder are you using? If custom, can you provide the output from
pack inspect-builder <builder>
?Can you provide a sample app or relevant configuration (
buildpack.yml
,nginx.conf
, etc.)?Checklist
The text was updated successfully, but these errors were encountered: