Marc Funaro
03/09/2023, 6:12 PMlucee/lucee:5.3.9.160-light-nginx and Snyk is reporting 190 vulnerabilities (12 critical, 17 high, 8 medium, and 85 low) -- all apparently the result of the BASE image, tomcat:9.0.65-jdk11-openjdk-bullseye . The Snyk interface reports an "Alternative upgrade" base image, tomcat:9-jdk11 , having only 3 medium vulnerabilities and 9 low. Is anyone else encountering this, and do you have any resolution advice?Marc Funaro
03/09/2023, 8:42 PMlucee/lucee:5.3.10.120-light-nginx-tomcat9.0-jdk11-openjdk-2303 and adding the following to the dockerfile reduces the number of vulnerabilties considerably. All the issues reported currently have no fix; only 2 high and 2 critical are reported, the rest are all low (with zero medium):
# Update package cache, then perform upgrades
RUN apt-get update \
&& apt-get -y upgrade \
&& apt-get -y dist-upgrade
In case this helps anyone else.