Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
NO-ISSUE: Run microdnf upgrade in image builds to resolve fixable vul…
…nerable dependencies (#1399) The update/upgrade command in dnf has flags `--security` and `--secseverity=Moderate`. Since `microdnf` does not have this sophisticated handling, and installing full `dnf` is by itself increasing the cve exposure surface significantly, we need to do with some restrictive set of flags of `microdnf` to make it update what it can, but no more. What's in the commit is stolen from https://stackoverflow.com/questions/61662403/microdnf-update-command-installs-new-packages-instead-of-just-updating-existing. (cherry picked from commit 94775eb)
- Loading branch information