Skip to content

Conversation

@echoix
Copy link
Collaborator

@echoix echoix commented Apr 5, 2025

Fixes Trivy vulnerability CVE-2025-31115 for xz in this case, but also future fixed ones too by always upgrading installed packages between respond of the base image.

Proposed Changes

Readiness Checklist

Author/Contributor

  • Add entry to the CHANGELOG listing the change and linking to the corresponding issue (if appropriate)
  • If documentation is needed for this change, has that been included in this pull request

Reviewing Maintainer

  • Label as breaking if this is a large fundamental change
  • Label as either automation, bug, documentation, enhancement, infrastructure, or performance

@echoix echoix enabled auto-merge (squash) April 5, 2025 19:10
@echoix echoix mentioned this pull request Apr 5, 2025
4 tasks
@echoix echoix merged commit 524d9f8 into oxsecurity:main Apr 5, 2025
6 of 7 checks passed
@echoix echoix deleted the xz-utils-install branch May 17, 2025 16:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants