<#92 Upgrade to at least ruby:2.7.6-alpine3.16> Is...
# pact-broker
g
#92 Upgrade to at least ruby:2.7.6-alpine3.16 Issue created by jorander Pre issue-raising checklist I have already (please mark the applicable with an
x
): ☑︎ Confirmed this is the right place to raise the issue - only issues related to the Dockerization of the Pact Broker should be raised here. Issues related to the Pact Broker application itself should be raised in the Pact Broker project. ☑︎ Upgraded to the latest Pact Broker Docker image OR ☑︎ Checked the </CHANGELOG.md|CHANGELOG> to see if the issue I am about to raise has been fixed ☑︎ Read the Troubleshooting page Software versions • pact-broker docker version: 2.105.0.1 Expected behaviour No known vulnerabilities. Actual behaviour Image apline3.15 contains three packages with known vulnerabilities that are all fixed and upgraded in alpine3.16: • gdbm: fixed in gdbm-1.23 • sqlite: CVE-2021-46100 (not disclosed but seems to be fixed in ver 3.37.0) • icu-libs: fixed in version 71.1-rc2 Steps to reproduce Security scan provided by Jfrog Xray. Relevent log files N/A pact-foundation/pact-broker-docker