From d7040e393307ad28493aa8ab1e4e7acfe808005d Mon Sep 17 00:00:00 2001 From: Matthias Fax Date: Sun, 18 Nov 2018 16:55:24 +0100 Subject: [PATCH] Bump Alpine version to 3.8 There has been a security issue with older Alpine versions and their package manager. https://justi.cz/security/2018/09/13/alpine-apk-rce.html Not sure about 3.7, but the latest 3.8 image has it fixed. --- Dockerfile | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Dockerfile b/Dockerfile index b82fac25..e7d75a42 100644 --- a/Dockerfile +++ b/Dockerfile @@ -16,7 +16,7 @@ RUN CGO_ENABLED=0 make local build # Choose alpine as a base image to make this useful for CI, as many # CI tools expect an interactive shell inside the container -FROM alpine:3.7 as production +FROM alpine:3.8 as production COPY --from=builder /go/src/mikefarah/yq/yq /usr/bin/yq RUN chmod +x /usr/bin/yq