Skip to content
Snippets Groups Projects
Unverified Commit 6d758d20 authored by Dave Hay's avatar Dave Hay Committed by GitHub
Browse files

Update/upgrade Alpine before installing openssl (#981)


Mitigating CVE-2021-3711 and CVE-2021-3712

Signed-off-by: default avatarDave Hay <david_hay@uk.ibm.com>

Co-authored-by: default avatarYoav Rotem <yoavrotems97@gmail.com>
parent b238a18a
No related branches found
No related tags found
No related merge requests found
......@@ -22,7 +22,8 @@ RUN apk --no-cache upgrade apk-tools
# Openssl is used by OpenShift tests
# https://github.com/aquasecurity/kube-bench/issues/535
RUN apk --no-cache add openssl
# Ensuring that we update/upgrade before installing openssl, to mitigate CVE-2021-3711 and CVE-2021-3712
RUN apk update && apk upgrade && apk --no-cache add openssl
# Add glibc for running oc command
RUN wget -q -O /etc/apk/keys/sgerrand.rsa.pub https://alpine-pkgs.sgerrand.com/sgerrand.rsa.pub
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Please register or to comment