Repository navigation
refactor(web): stop upgrading base packages during build - #77
vitormattos wants to merge 1 commit into
Conversation
Signed-off-by: Vitor Mattos <1079143+vitormattos@users.noreply.github.com>
|
The CI failure shows that this change is not safe to merge as-is. Without
The Trivy gate is therefore behaving correctly. Also, Closing this PR rather than weakening the vulnerability policy or adding CVE exceptions. A future base-image reproducibility change should first pin/update the base image and prove that the resulting image passes Trivy without a blanket package upgrade. |
Closes #68.
Part of #47.
The web image should inherit its package set from the selected
nginx:alpinebase instead of mutating that base with a blanketapk upgrade --no-cacheduring every build.This PR removes the blanket upgrade.
Base-image updates remain explicit and reviewable through Dependabot, and the existing image build/Trivy workflow continues to detect vulnerable packages.
This keeps the image reproducible from its declared base and avoids silently changing all Alpine packages when the Dockerfile itself has not changed.