Result
This change was evaluated in #77 and should not be applied in isolation.
Removing apk upgrade --no-cache from the current nginx:alpine build caused the Trivy security gate to detect two HIGH vulnerabilities with fixes already available in the Alpine repositories:
The existing upgrade therefore currently closes a real security gap between the published nginx:alpine image and newer packages available from the Alpine repository.
The original reproducibility argument was also incomplete: nginx:alpine is itself a moving tag, so removing the package upgrade alone does not make builds reproducible.
Decision
Do not remove the blanket Alpine upgrade until the base-image lifecycle is redesigned.
A future change should consider:
- pinning the Nginx base image by digest;
- having dependency automation update that digest;
- verifying that the updated base passes Trivy without package mutation;
- only then removing
apk upgrade --no-cache if it is no longer required.
Closed as not planned in its current form.
Part of #47.
Result
This change was evaluated in #77 and should not be applied in isolation.
Removing
apk upgrade --no-cachefrom the currentnginx:alpinebuild caused the Trivy security gate to detect two HIGH vulnerabilities with fixes already available in the Alpine repositories:libexpat/ CVE-2026-93990: 2.8.4-r0 -> 2.8.5-r0;pcre2/ CVE-2026-103111: 10.48-r0 -> 10.49-r0.The existing upgrade therefore currently closes a real security gap between the published
nginx:alpineimage and newer packages available from the Alpine repository.The original reproducibility argument was also incomplete:
nginx:alpineis itself a moving tag, so removing the package upgrade alone does not make builds reproducible.Decision
Do not remove the blanket Alpine upgrade until the base-image lifecycle is redesigned.
A future change should consider:
apk upgrade --no-cacheif it is no longer required.Closed as not planned in its current form.
Part of #47.