Skip to content

Conversation

@showwin
Copy link
Contributor

@showwin showwin commented May 21, 2025

Changes

Upgrade all library versions to latest to fix vulnerabilities.

Context

apt update and apt install doesn't update the installed libs, so if the base image has a library with vulnerability, we are using that version in Production.

Ticket

https://degica.atlassian.net/browse/SR-1034

Test

Before this change
Screenshot 2025-05-21 at 16 21 56

After this change
Screenshot 2025-05-21 at 16 21 31

But we have only 2 critical CVEs in Production for some reason, so not sure if this can really fix the CVEs in Prod.
Screenshot 2025-05-21 at 16 33 29

@showwin showwin requested a review from a team as a code owner May 21, 2025 07:00
@showwin showwin requested review from essa and removed request for a team May 21, 2025 07:00
@showwin showwin changed the title Add apt upgrade process to apply security patch to installed libs Add apt upgrade to apply security patch to installed libs May 21, 2025
Copy link

@essa essa left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM 👍
But unattended-upgrade may be safer.

@showwin showwin added this pull request to the merge queue May 22, 2025
Merged via the queue into master with commit e58d76f May 22, 2025
6 checks passed
@showwin showwin deleted the sec-update branch May 22, 2025 02:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants