mirror of
https://github.com/fleetdm/fleet
synced 2026-05-24 09:28:54 +00:00
Resolves #43671. Bumps the Alpine base image from 3.23.3 to 3.23.4 in the Dockerfiles that produce published images, picking up patched openssl, musl, and zlib packages. Follows the same pattern as #38977. ### CVEs resolved - HIGH: CVE-2026-28388, CVE-2026-28389, CVE-2026-28390, CVE-2026-31790, CVE-2026-2673, CVE-2026-40200 - MEDIUM: CVE-2026-27171, CVE-2026-6042, CVE-2026-22184 ### Test plan - CI image build passes. - Trivy/ECR scan on the resulting fleetdm/fleet image confirms the nine listed CVEs are gone. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Chores** * Updated Docker base images to Alpine 3.23.4 across infrastructure and deployment components for improved stability and security. <!-- end of auto-generated comment: release notes by coderabbit.ai -->
14 lines
331 B
Docker
14 lines
331 B
Docker
FROM alpine:3.23.4@sha256:5b10f432ef3da1b8d4c7eb6c487f2f5a8f096bc91145e68878dd4a5019afde11
|
|
LABEL maintainer="Fleet Developers"
|
|
|
|
RUN apk --update add ca-certificates
|
|
RUN apk --no-cache add jq
|
|
|
|
# Create fleet group and user
|
|
RUN addgroup -S fleet && adduser -S fleet -G fleet
|
|
|
|
USER fleet
|
|
|
|
COPY fleet /usr/bin/
|
|
|
|
CMD ["fleet", "serve"]
|