Closed
Description
Are there any plans to upgrade openjdk:8-alpine to alpine version 3.10? Doing this would remove vulnerabilities. These are shown in the snippet below (scan results from Anchore):
Vulnerability ID Package Severity Fix CVE Refs Vulnerability URL
CVE-2018-1000654 libtasn1-4.13-r0 High 4.14-r0 CVE-2018-1000654 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1000654
CVE-2019-12900 libbz2-1.0.6-r6 High 1.0.6-r7 CVE-2019-12900 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-12900
CVE-2019-14697 musl-1.1.20-r4 High 1.1.20-r5 CVE-2019-14697 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14697
CVE-2019-14697 musl-utils-1.1.20-r4 High 1.1.20-r5 CVE-2019-14697 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14697
CVE-2019-8457 sqlite-libs-3.26.0-r3 High 3.28.0-r0 CVE-2019-8457 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-8457
Metadata
Metadata
Assignees
Labels
No labels