Skip to content

build(deps): base docker image off latest Alpine with updated DB driver versions#8277

Merged
jeremylong merged 1 commit intodependency-check:mainfrom
chadlwilson:alpine-323
Feb 3, 2026
Merged

build(deps): base docker image off latest Alpine with updated DB driver versions#8277
jeremylong merged 1 commit intodependency-check:mainfrom
chadlwilson:alpine-323

Conversation

@chadlwilson
Copy link
Collaborator

@chadlwilson chadlwilson commented Feb 3, 2026

Description of Change

We use mutable tags for the golang and JVM layers which move Alpine versions over time, so we probably should be consistent with the main base image, which is a dotnet runtime image. Right now we are using a golang and JVM built off Alpine 3.2e while running on Alpine 3.22.

While that should not generally be an issue; it might be, as I don't think Java is statically compiled; still dynamically linked to musl libc.verisins which can different across Alpine releases.

The alternative change here is to use specific Alpine versions and update them together - there are possibly ways to trick dependabot into being able to do this if we'd rather go use an Alpine-feature-mutating tag.

Also bumps the bundled driver versions to latest.

Related issues

N/A

Have test cases been added to cover the new functionality?

yes

…versions

Signed-off-by: Chad Wilson <29788154+chadlwilson@users.noreply.github.com>
Copy link
Collaborator

@jeremylong jeremylong left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@jeremylong jeremylong merged commit 1a2bfc0 into dependency-check:main Feb 3, 2026
9 checks passed
@jeremylong jeremylong added this to the 12.2.1 milestone Feb 3, 2026
@chadlwilson chadlwilson deleted the alpine-323 branch February 4, 2026 18:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants