Skip to content

Stop upgrading Alpine packages inside the web image build #68

Description

@vitormattos

Result

This change was evaluated in #77 and should not be applied in isolation.

Removing apk upgrade --no-cache from the current nginx:alpine build caused the Trivy security gate to detect two HIGH vulnerabilities with fixes already available in the Alpine repositories:

The existing upgrade therefore currently closes a real security gap between the published nginx:alpine image and newer packages available from the Alpine repository.

The original reproducibility argument was also incomplete: nginx:alpine is itself a moving tag, so removing the package upgrade alone does not make builds reproducible.

Decision

Do not remove the blanket Alpine upgrade until the base-image lifecycle is redesigned.

A future change should consider:

  • pinning the Nginx base image by digest;
  • having dependency automation update that digest;
  • verifying that the updated base passes Trivy without package mutation;
  • only then removing apk upgrade --no-cache if it is no longer required.

Closed as not planned in its current form.

Part of #47.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions