Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Out-of-date base images #1482

Open
cjmyers opened this issue Dec 13, 2021 · 0 comments
Open

Out-of-date base images #1482

cjmyers opened this issue Dec 13, 2021 · 0 comments

Comments

@cjmyers
Copy link
Collaborator

cjmyers commented Dec 13, 2021

Regarding out-of-date base images:

  • The virtuoso docker image is built on Ubuntu 16.04, which is out of support.
  • The autoheal docker image is based on Alpine 3.13.5, which has some security issues fixed in the next release.
  • The synbiohub docker image is based on Node v11.1.0 and Alpine 3.8.1, both of which have security issues fixed in later releases.

Docker.com has made a tool called Snyk available to check containers for vulnerabilities. The SynBioHub team might want to try it out. I would guess that we (NIST/MML) will want to build the containers from scratch so we can keep track of what’s inside and to update them at will.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant