Skip to content

Commit 92f4ed7

Browse files
committed
Upgrade base image to debian 12, upgrade packages and openresty to cve free version
Signed-off-by: Dom Del Nano <ddelnano@gmail.com>
1 parent ce714e6 commit 92f4ed7

3 files changed

Lines changed: 13 additions & 13 deletions

File tree

bazel/container_images.bzl

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -42,18 +42,18 @@ def _container_image(name, digest, repository):
4242
)
4343

4444
def base_images():
45-
# Based on alpine 3.15.9, using OpenResty 1.21.4.1
46-
# https://hub.docker.com/layers/openresty/openresty/alpine-apk-amd64/images/sha256-2259f28de01f85c22e32b6964254a4551c54a1d554cd4b5f1615d7497e1a09ce?context=explore
45+
# Based on alpine 3.18.12, using OpenResty 1.27.1.2
46+
# https://hub.docker.com/r/openresty/openresty/tags?name=1.27.1.2-11-alpine-apk
4747
_container_image(
4848
name = "openresty",
4949
repository = "openresty/openresty",
50-
digest = "sha256:2259f28de01f85c22e32b6964254a4551c54a1d554cd4b5f1615d7497e1a09ce",
50+
digest = "sha256:56fc9f7abc449a6d3eb06f63eca536fb61c16a3a53ab3fa7b9bb4dd6af614787",
5151
)
5252

5353
_container_image(
5454
name = "base_image",
55-
repository = "distroless/base",
56-
digest = "sha256:8267a5d9fa15a538227a8850e81cf6c548a78de73458e99a67e8799bbffb1ba0",
55+
repository = "distroless/base-debian12",
56+
digest = "sha256:1f144c77a9ecaaa132fc3037b4417d9f9fd0b7a50101c696af5cb186876aa2a3",
5757
)
5858

5959
_container_image(

bazel/external/ubuntu_packages/debs.json

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -12,16 +12,16 @@
1212
"checksum": "9a9aee10c7804ff678719fb2887fa4758d5d94c7cb03c1b50fbccb0c4ee43dcc"
1313
},
1414
{
15-
"path": "main/n/ncurses/libtinfo6_6.4-2_amd64.deb",
16-
"checksum": "9627a3d3d2b9fed9fc5828962a52a6f70de8bb73dca9a9a432cab4b0159e68cb"
15+
"path": "main/n/ncurses/libtinfo6_6.4-4_amd64.deb",
16+
"checksum": "072d908f38f51090ca28ca5afa3b46b2957dc61fe35094c0b851426859a49a51"
1717
},
1818
{
1919
"path": "main/libu/libunwind/libunwind8_1.6.2-3_amd64.deb",
2020
"checksum": "571cb2968ba9eaa817ae3bad792e4dbb80950c72d28b92ea3ea67becd08e8711"
2121
},
2222
{
23-
"path": "main/x/xz-utils/liblzma5_5.4.1-0.2_amd64.deb",
24-
"checksum": "2c9c51f281997ce5963e3b22b928dec13adafb8e3079bc02f89e51db9891bfd2"
23+
"path": "main/x/xz-utils/liblzma5_5.4.1-1_amd64.deb",
24+
"checksum": "d321b9502b16aac534e1c691afbe3dc5e125e5091aa35bea026c59b25ebe82e7"
2525
},
2626
{
2727
"path": "main/z/zlib/zlib1g_1.2.13.dfsg-1ubuntu4_amd64.deb",

bazel/external/ubuntu_packages/packages.bzl

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -38,14 +38,14 @@ def download_ubuntu_packages():
3838
)
3939
http_file(
4040
name = "liblzma5",
41-
urls = ["https://storage.googleapis.com/pixie-dev-public/ubuntu-debs/1655507056/liblzma5_5.4.1-0.2_amd64.deb"],
42-
sha256 = "2eb9eec6d213ea17938ef5c552f360a1093386acfe185e8c7cccdc60b984744d",
41+
urls = ["http://deb.debian.org/debian/pool/main/x/xz-utils/liblzma5_5.4.1-1_amd64.deb"],
42+
sha256 = "d321b9502b16aac534e1c691afbe3dc5e125e5091aa35bea026c59b25ebe82e7",
4343
downloaded_file_path = "out.deb",
4444
)
4545
http_file(
4646
name = "libtinfo6",
47-
urls = ["https://storage.googleapis.com/pixie-dev-public/ubuntu-debs/1655507056/libtinfo6_6.4-2_amd64.deb"],
48-
sha256 = "9d857ace717312b56acf7775b23e6400eef98c1eb7b0db111a799709c6d97353",
47+
urls = ["http://deb.debian.org/debian/pool/main/n/ncurses/libtinfo6_6.4-4_amd64.deb"],
48+
sha256 = "072d908f38f51090ca28ca5afa3b46b2957dc61fe35094c0b851426859a49a51",
4949
downloaded_file_path = "out.deb",
5050
)
5151
http_file(

0 commit comments

Comments
 (0)