From 254f87c61a6d3b26abe545c844f84e8c311e25ec Mon Sep 17 00:00:00 2001 From: Hidde Beydals Date: Thu, 7 Mar 2019 17:48:02 +0100 Subject: [PATCH] Bump Alpine version from v3.6 to v3.9 We have multiple nightly builds (from `44874ead` up to and including `c9cda8ab` at time of this commit) with gnupg 2.1.20-r1 baked into them which is effected by CVE-2018-12020 (patched in >=2.2.3-r1). As there is no newer version of gnupg available in the Alpine main/v3.6 repository, and 3.6 is only receiving security updates (but with a delay?), and supports for 3.6 ends on 2019-05-01, this bump is mandatory. --- docker/Dockerfile.flux | 2 +- docker/Dockerfile.helm-operator | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/docker/Dockerfile.flux b/docker/Dockerfile.flux index 4fe5d388d..30926ae23 100644 --- a/docker/Dockerfile.flux +++ b/docker/Dockerfile.flux @@ -1,4 +1,4 @@ -FROM alpine:3.6 +FROM alpine:3.9 WORKDIR /home/flux diff --git a/docker/Dockerfile.helm-operator b/docker/Dockerfile.helm-operator index 812c2fb82..04cfcd739 100644 --- a/docker/Dockerfile.helm-operator +++ b/docker/Dockerfile.helm-operator @@ -1,4 +1,4 @@ -FROM alpine:3.6 +FROM alpine:3.9 WORKDIR /home/flux