SBCOSS-412: Updated Docker file for image level vulnerability fix - #214
Merged
pallakartheekreddy merged 2 commits intoJul 28, 2025
Merged
Conversation
Img level vul fixes
pallakartheekreddy
approved these changes
Jul 28, 2025
pallakartheekreddy
merged commit Jul 28, 2025
3d127f6
into
Sunbird-Lern:release-5.0.2
1 of 2 checks passed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Please include a summary of the change and which issue is fixed. Please also include relevant motivation and context. List any dependencies that are required for this change.
Type of change
Please choose appropriate options.
How Has This Been Tested?
Please describe the tests that you ran to verify your changes in the below checkboxes. Provide instructions so we can reproduce. Please also list any relevant details for your test configuration
Test Configuration:
Checklist:
Description by Korbit AI
What change is being made?
Update the Dockerfile to fix image-level vulnerabilities by upgrading packages using
apk upgrade, adding missing no-cache flags, consolidating package additions, and cleaning up cache after installation.Why are these changes being made?
The changes address security vulnerabilities present in the Docker image by ensuring that all installed packages are updated to their latest versions and unnecessary caches are removed to reduce the attack surface and overall image size. This approach follows best practices for building secure and efficient Docker images.