GitHub
12/22/2022, 3:55 PMx):
☑︎ Confirmed this is the right place to raise the issue - only issues related to the Dockerization of the Pact Broker should be raised here. Issues related to the Pact Broker application itself should be raised in the Pact Broker project.
☑︎ Upgraded to the latest Pact Broker Docker image OR
☑︎ Checked the </CHANGELOG.md|CHANGELOG> to see if the issue I am about to raise has been fixed
☑︎ Read the Troubleshooting page
Software versions
• pact-broker docker version: 2.105.0.1
Expected behaviour
No known vulnerabilities.
Actual behaviour
The documentation for setting up database connectivity describes PostgreSQL (for production) and SQLite (for testing), but it doesn't mention MariaDB. Still the mariadb-dev package is brought in as a dependency in the Docker image. MariaDB version 10.6.10 seems to have quite a few security issues, some not fixed in later versions either.
• https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-27385
• https://jira.mariadb.org/browse/MDEV-26911
• https://jira.mariadb.org/browse/MDEV-27001
• https://jira.mariadb.org/browse/MDEV-26956
• https://jira.mariadb.org/browse/MDEV-26589
• https://jira.mariadb.org/browse/MDEV-26590
• https://jira.mariadb.org/browse/MDEV-26556
• https://jira.mariadb.org/browse/MDEV-26561
• https://jira.mariadb.org/browse/MDEV-26574
Question: Is MariaDB used for some internal tasks, or could it be removed from the pact-broker-docker image?
Steps to reproduce
Security scan provided by Jfrog Xray.
Relevent log files
N/A
pact-foundation/pact-broker-docker