You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
I think we should not use the distroless/base image as intermediate one until there is bookworm version. Because when we install libraries inside this distroless/base, it will install libraries, like openssh, libssl1.1 etc. for the OS 11. In that case, it retrieves the vulnerabilities of the version 11. Then these libraries are copied from the intermediate image to the final one.
distroless serves the purpose of populating things like /etc and /dev and ca-certificates.
To drop distroless we either do that all ourselves or we find a workable replacement. chainguard's static may fit the bill, but it purports to be alpine instead of debian, so I'm not sure it will be as easy as I'd like.
Out of time for today, but this is clearly a v4 release blocker.
The text was updated successfully, but these errors were encountered: