Topic: Lucee Docker Image and Snyk Q: We are curre...
# lucee
m
Topic: Lucee Docker Image and Snyk Q: We are currently using docker image
lucee/lucee:5.3.9.160-light-nginx
and Snyk is reporting 190 vulnerabilities (12 critical, 17 high, 8 medium, and 85 low) -- all apparently the result of the BASE image,
tomcat:9.0.65-jdk11-openjdk-bullseye
. The Snyk interface reports an "Alternative upgrade" base image,
tomcat:9-jdk11
, having only 3 medium vulnerabilities and 9 low. Is anyone else encountering this, and do you have any resolution advice?
UPDATE: Changing to image
lucee/lucee:5.3.10.120-light-nginx-tomcat9.0-jdk11-openjdk-2303
and adding the following to the dockerfile reduces the number of vulnerabilties considerably. All the issues reported currently have no fix; only 2 high and 2 critical are reported, the rest are all low (with zero medium):
Copy code
# Update package cache, then perform upgrades
RUN apt-get update \
	&& apt-get -y upgrade \
	&& apt-get -y dist-upgrade
In case this helps anyone else.